Skip to content
Preprint

PolicyGuide: From Guarding One Action to Guiding the Whole Workflow for Policy-Compliant LLM Agents

Aug 2026 · 2 citations · 47 references
Computer Science

TL;DR

PolicyGuide compiles each domain policy into a workflow graph and invokes a proactive verifier at user-turn boundaries and finds the lowest observed attack-success rate under adversarial users and the strongest procedural compliance in an author-designed workflow-level validation.

Abstract

Customer-service LLM agents must follow organizational policy when acting on a user's behalf. Compliance failures arise from either forbidden actions, such as granting an ineligible change, or omitted procedural requirements, such as identification or confirmation. Runtime safeguards can intervene on risky actions, but action-local checks do not guide an agent through a multi-step procedure. Workflow-following systems support prescribed process execution, but primarily target workflow completion rather than safeguarding agent behavior. PolicyGuide instead compiles each domain policy into a workflow graph and invokes a proactive verifier at user-turn boundaries. From persisted graph state, the verifier reconciles open requests and returns step-specific remediation along a policy-compliant path. Across the $\tau^2$-bench airline, retail, and telecom domains with a GPT-5.4 agent and verifier, PolicyGuide raises mean $\mathrm{Pass}^4$ from $0.42$ to $0.62$, with the largest gain on telecom ($0.19$ to $0.61$), the most workflow-structured domain. The same workflows transfer to Claude Sonnet 4.6 and Gemini 2.5 Pro agents. Complementary evaluations find the lowest observed attack-success rate under adversarial users and the strongest procedural compliance in an author-designed workflow-level validation.

View source

Similar papers

Preprint Aug 2026

AgentFlow: A Flow-Centric Policy Language and Framework for Securing LLM Agent Systems

AgentFlow, a flow-centric policy language and runtime enforcement model for specifying where data may travel in agent systems, is presented and results are preliminary and scoped to the modeled policy-visible agent behaviors and evaluated benchmarks.

B. Shivakumar, Swarn Priya, Peng Gao · 2 citations
#artificial intelligence Review Sep 2026

Compositional Policy Violations: When Step-Level Compliance Fails In Agentic AI Workflows

Agentic workflows now make consequential decisions in regulated settings, and the governance placed around them is almost entirely step-scoped: input-output classifiers, per turn rails, and span-level evaluators. The policies organizations actually hold, such as referral thresholds, authority limits, and review require...

Ashwini Kurady, S. Grandhi, R. Gupta et al. · 0 citations
Jul 2026

ReATest: enhancing policy-as-code workflows through automated test case generation from Rego policies

ReATest is introduced, an automated approach to enhancing PaC workflows through systematic test case generation from Rego specifications, which achieves an average 35.43% reduction in test suite size and retains 64.57% of the generated test cases.

Thanh-Binh Trinh, N. Le, H. Nguyen · 0 citations
#artificial intelligence Preprint Sep 2026

Autonomy in Check: Governor-Mediated Adaptive Security at the Edge

Adaptive security at the network edge increasingly relies on automated planners, including rule-based controllers, learned policies, and LLM-assisted agents, that translate observations into enforcement actions. Once such a planner can influence live policy state, syntactic validity is not enough. A semantically wrong...

Ijaz Ahmad, Flavio Esposito, Erkki Harjula · 0 citations
Review Aug 2026

Stateful Governance for Concurrent Agentic Systems

MasuGate is presented, a runtime architecture that keeps policies as reviewable programs while coordinating the state and effects needed to preserve their decisions, and suggests a path for integrating stateful governance boundaries into agent frameworks and provider-backed domains where agents act on shared resources.

Yuxiang Peng, Xiaodi Wu · 1 citation
#artificial intelligence Preprint Aug 2026

If Agents Were Angels, No Governance Would Be Necessary: Out-of-Band Policy Enforcement at a Trusted Tool Boundary

It is proved, under stated conditions, that the policy plan is order-independent and agent policy cannot widen the ceiling, and it is shown that write controls, durable approval, and temporal and aggregate policies lie outside this evaluation.

Marc Millstone, Tyler Akidau, Johannes Brüderl et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.