Reference
FAQ
What Is botYguard?
botYguard is a security and governance layer for AI agents. It helps teams enforce policies, manage approvals, protect secrets, connect integrations, and keep audit visibility over hosted or MCP-connected agent actions.
What Is The Difference Between MCP And Container Or Hosted?
MCP is for connecting existing agents or agents you do not fully control. The external agent calls botYguard through an MCP key or connector URL.
Container or hosted means botYguard runs a custom agent for the user’s specific use case. Use this when you want botYguard to own more of the agent runtime.
Does botYguard Secure MCP Agents?
Yes. MCP-connected agents can route through botYguard with an MCP API key or connector URL. botYguard applies the assigned profile, policy, secrets handling, approval rules, and audit logging before the agent reaches governed tools.
How Long Is A Hosted Agent Active?
Hosted-agent lifetime depends on the deployment and session settings chosen in the dashboard. For MCP keys and connector URLs, use the TTL or expiration fields shown during creation.
How Do I Add Secrets?
Add runtime model keys in Settings -> Provider Settings. Add integration credentials through the integration flow, such as Google Workspace OAuth. Do not paste provider secrets, Google refresh tokens, or admin credentials into external agent prompts.
How Does botYguard Protect Secrets?
botYguard keeps provider keys, integration credentials, and private context out of agent prompts and external instructions. Approved credentials are passed only through governed execution paths when policy allows the requested action.
What If I Do Not Have An API Key?
You can still sign in, create the tenant, connect Google Workspace, and draft policies manually with the form. You need a supported provider key for hosted-agent runtime usage and AI-assisted policy generation.
Where Can I See My Agent’s Actions?
Use the agent details, policy decision logs, audit views, and integration status pages in the dashboard. These show what the agent attempted, what policy decided, and whether an action was allowed, denied, audited, redacted, or sent for approval.
How Do Approvals And Audit Logs Work?
Policies can require approval before sensitive actions run. botYguard records the request, policy decision, approval result, tool access, provider usage, and integration activity so teams can review what happened later.
Do Google Workspace Integrations Grant Access Automatically?
No. Connecting Google Workspace creates an available integration. Policies decide which agents can use Drive, Gmail, and Calendar, and which actions are allowed.
Should I Assign Policies To An Agent Type Or One Agent?
Assign to an agent type for shared defaults across similar agents. Assign to a specific agent when you need narrower permissions, testing, or a one-off exception.
When Should I Use Redaction?
Use redaction when logs or agent messages may contain customer data, personal data, confidential documents, or private chat content. In Discord, configure redaction terms with /botyguard redact set; botYguard redacts those values before the agent sees them and rehydrates the chat response where appropriate.
Can The Policy Generator Create My First Policy?
Yes. The generator can use your provider API key to draft a policy from plain English. Review the generated policy before saving, especially resource scope, allowed actions, audit behavior, and write/delete handling.
Can I Connect More Than Google Workspace?
Google Workspace currently covers Drive, Gmail, and Calendar. More integrations and capabilities are planned, so keep policies scoped to the integrations that are available in your tenant today.