Definitions · R
Runtime Agent Enforcement
Runtime agent enforcement evaluates and controls tool calls, prompts, and egress while an agent is executing — not only at login or API gateway time. Blekline applies allow, mask, or block decisions before downstream systems act.
Runtime agent enforcement applies policy during agent execution: on tool calls, prompts, and egress — not only at identity login or API gateway admission.
Blekline actions
- Allow — proceed with optional secret masking
- Mask — redact sensitive args before downstream
- Block — kill the tool call or session path
Open-core enforcement runs via @blekline/contracts locally; cloud and sidecar add fleet policy and NHIM features.