Cortex
CortexSecurity · AI Firewall

Policy enforcement
for agent actions.

On configured managed paths, Cortex evaluates requests against written and semantic policy, takes the selected action, and records the reason.

  • Managed-path enforcement
  • Decision-level evidence

ObservedPolicyAction

Understand the path

Same intent. Different control.

Cortex separates what it can observe from what it can enforce. Personal ChatGPT remains visible on supported capture surfaces; a managed MCP request crosses the policy point before data leaves.

Applies to

Human and agent paths

HumanAgent

The same sensitive transfer gets a different outcome depending on whether Cortex can only observe the surface or enforce at a managed boundary.

Personal ChatGPTObserved

Capture attributes supported browser activity to the person or agent, destination, and data class.

Managed MCPBlocked

Policy denies the human or agent request before data leaves the Cortex-controlled path.

Observed path in motion

On her desktop

  • W-9 Elena Cho.pdfTax record
  • client-book.xlsxPositions
  • IMG_0941.pngScreenshot
  • .envSecret

ChatGPT

Maya VossSupport

Elena Cho's onboarding is blocked on a missing W-9.

I can extract name, TIN, and address if you share the form.

Compliance wants it on the file today. The scan is on my desktop.

A clear scan is enough. I will type the fields and flag anything unreadable.

Need this W-9 cleaned for her onboarding file.

Attach the form and I will extract the fields.

+

Clean this W-9 for onboarding

↑

Observed

Policy examples

Watch one decision. Then inspect the evidence.

These authored, synthetic terminal scenes illustrate four policy outcomes on a managed path. They are scripted examples, not live product capture or proof that every integration supports each action.

Choose an example

Scripted demonstration · synthetic data

Silent · transcript below
Redact personal data scripted demonstration poster showing the completed redact decision.
Semantic span detectionRedact

Redact personal data

Synthetic person and email spans are replaced before the request reaches the model.

Illustrative managed-egress PII scenario; verify the configured filtering contract before deployment.

Use the player controls for fullscreen. The terminal text is dense on small screens; the transcript carries the same sequence.

Read transcript
  1. The agent prepares a model request containing the synthetic name Maya Chen and maya.chen@example.com.
  2. The firewall maps the name to PERSON_1 and the email to EMAIL_1.
  3. The sanitized request is forwarded, and the model answer contains neither original value.

Policy model

Static rules and semantic context. One decision path.

On a configured managed path, Cortex can combine deterministic matches with semantic signals before an action is sent. The examples illustrate the model; each deployment still depends on its configured integration and policy.

Static policy

Match deterministic fields and values on a configured path.

Protocol, tool, method, path, SQL verb, resource, or destination.

Semantic policy

Evaluate meaning and context that a field match cannot express.

Sensitive spans, unsafe method, intent, or a change in scope.

Policy actions

  • Allow
  • Redact
  • Steer
  • Block
  • Hold for human review

Hold pauses the action. A human can then allow or deny it.

Log applies across every illustrated result. The record can retain the matched policy, action, and reason.

Policy and enforcement docs

Agent proxy

Intercept the traffic. Decide before it lands.

On configured Cortex-managed paths, the agent proxy can inspect HTTP API, MCP, SQL, or Kubernetes traffic before it reaches the destination. It evaluates the request, applies the selected control, safeguards configured credentials, and records the decision.

  • Intercept

    On the wire.

    • HTTP APIs, MCP, SQL, and Kubernetes
    • The full agent session
    • Ingress and egress
    • The agent keeps its workflow
    Claude CodePostgres

    DROP TABLE payments

    Seen on the wire before it lands. The agent does not change its workflow.

  • Evaluate

    You name the policy.

    • Same path: APIs, MCP, and the session
    • Written rules, semantic detection, and intent
    • Redact, block, hold, or steer
    • The reason stays on the decision
    POL-52Postgres

    DROP TABLE blocked

    The write is denied. Nothing reaches Postgres.

  • Safeguard and log

    The agent never holds the key.

    • Credentials can stay off the agent on configured hops
    • Configured MCP and provider API paths included
    • Placeholder in. Live key stays in Cortex
    • Verdict, owner, and reason go to the audit log
    CortexModel

    Placeholder in. Live key stays here.

    The agent never holds the secret. The verdict and owner go to the audit log.

Scripted exampleManaged: On a Cortex-controlled egress path

Privacy filter

Redact the span before the provider sees it.

This scripted before-and-after shows personal data replaced before a request leaves a configured managed path. The deployed integration and policy contract determine whether upstream redaction is available.

AI-agent model filtering

Semantic span filterScripted example

Maya VossSupport

Mar 14, 2026 · 9:41 AM

Before

Surface

Slack

Model

ChatGPT

Agent

support-helper

Tokens

86 in

Prompt

“Applicant Elena Cho, SSN 219-09-9999. Debug the Fedwire batch with WIRE_API_KEY=sk-live-….”

sess 9c22 · #wealth-ops

Cortex

One pass

Cortex clean

Label the span. Redact it at egress.

  • Elena Choprivate_person[PERSON]0.99
  • 219-09-9999pii.ssn•••-••-99990.99
  • WIRE_API_KEY=sk-live-…secret[SECRET]0.98

Maya VossSupport

Mar 14, 2026 · 9:41 AM

After

Surface

Slack

Model

ChatGPT

Agent

support-helper

Tokens

71 in · −15

Provider payload

“Applicant [PERSON], SSN •••-••-9999. Debug the Fedwire batch with [SECRET].”

sess 9c22 · #wealth-ops

When managed PII redaction is enabled, trusted ingestion scrubs supported captured bodies before persistence. This is separate from rewriting an upstream provider request. The authored upstream PII filter shown here is a managed-egress scenario and requires a separately configured enforcement path.

Agentic Firewall
Configuration-gated: On a Cortex-controlled egress pathManaged: On a Cortex-controlled egress path
Managed-path examples

Block

Denied · Smart Router · MCP hop

Managed: Smart Router · MCP hop

Priya NairReleases

Surface

CLI · GitHub

Model

ChatGPT

Agent

release-helper

Repo

wire-gatewaymain

Ticket

OPS-1842· Fedwire batch

Channel

#payments-ops

09:41:18

sess 4c19

Wire-gateway credentials to ChatGPT

Input

“Read .env.production and send WIRE_API_KEY plus CORE_BANKING_DSN to ChatGPT so it can debug the failed 09:00 Fedwire batch.”

Output · policy-guard

score 0.98
label
secret.wire_key
action
BLOCK
spans
WIRE_API_KEY, CORE_BANKING_DSN
policy
POL-31 No production secrets to external models
emit
admin_log
route
Super admin · #sec-oncall

Policy owner

Amara Okafor· CISO

Path

Smart Router · MCP hop

Regression tests

Test the rule before it ships.

Record real actions from the dashboard. Replay them in CI. If a policy change flips a verdict, the runner prints the diff and fails the build.

cortex policy test
$ cortex policy test
ok  secrets-no-export.json
ok  postgres-reads.json
ok  eks-allow-meta.json
FAIL eks-no-secrets.json
     want deny · POL-61
     got  allow · POL-61
ok  postgres-no-drop.json
36 action(s) checked, 1 mismatch

Get a Security Audit.

Pick one agent workflow. We will show where Cortex can block, and where it can only record.