Enterprise-style controls for Maine organizations

AI agent security for work that can take action.

AI Impact Maine helps organizations assess, secure, monitor, audit, and govern AI agents that can access files, use tools, execute commands, connect to business applications, and coordinate multi-step work.

Least privilege
Human approval
Reviewable records
Bounded deployment
Featured Managed Service

AI Agent Security, Monitoring, and Activity Auditing

Know what your AI agents can access—and what they attempted to do.

AIM AgentGuard is AI Impact Maine’s managed service for reviewing, monitoring, auditing, and governing AI agents that can access files, execute commands, use tools, connect to external systems, or coordinate work through sub-agents.

Visibility and governance for tool-using agents

The engagement maps agents, owners, authority, tools, data access, external destinations, approval points, and available activity records. Findings are translated into least-privilege recommendations, shutdown procedures, governance documentation, and a managed review plan appropriate to the supported environment.

Where Numbat may fit

Numbat may be used as one component of AIM AgentGuard when it supports the selected agent and deployment surface. It can provide local agent-activity visibility, policy evaluation, supported forensic reconstruction, and optional pre-action enforcement after controlled testing.

Numbat is an Apache-2.0 open-source project developed by Perplexity. AI Impact Maine is independent and is not affiliated with, endorsed by, or certified by Perplexity.

Service capabilities

  • Agent and sub-agent inventory
  • Agent ownership mapping
  • Tool-access review
  • File and folder permission review
  • Credential-handling review
  • Network-destination review
  • Monitor-only activity capture
  • Supported agent-session reconstruction
  • Commands, tools, and file activity review
  • Redacted incident timelines
  • Custom detection-policy planning
  • Human approval requirements
  • Least-privilege recommendations
  • Shutdown and rollback procedures
  • Governance documentation
  • Periodic managed review

Coverage and limitations

  • Coverage depends on the supported agent, hooks, integrations, and available logs.
  • Historical reconstruction may be incomplete.
  • Monitor-only operation does not block actions.
  • Enforcement is enabled only after testing and explicit client approval.
  • AIM AgentGuard does not replace endpoint protection, identity security, email security, DLP, network security, backups, or incident-response planning.
  • It is not advertised as a 24/7 SOC.
  • It does not detect deepfake videos, cloned voices, or general email spam.

When an assistant becomes an operator, the control model changes.

Designed for Maine businesses, nonprofits, municipalities, and professional teams in Portland and statewide that are testing or already using agents with meaningful access.

01

Leaders and owners

You need a clear inventory, accountable owners, approval boundaries, and a practical remediation plan before agent use expands.

02

IT and security teams

You need tool, identity, credential, logging, and network-destination context that fits existing security controls.

03

Operations teams

You need a bounded workflow that improves work without giving an agent more access or autonomy than the task requires.

Make access and accountability visible.

The work focuses on concrete control questions, not abstract promises of perfect safety.

Shadow agent use

Find agent tools and workflows that may be operating without a named owner, approved purpose, or review process.

Excessive permissions

Map file, shell, application, API, and network access against what the use case actually needs.

Credential exposure

Review how tokens, keys, sessions, and service accounts are made available to agents and sub-agents.

Unreviewed actions

Identify sensitive steps that need a person to approve, reject, correct, or stop the work.

Missing records

Assess whether supported prompts, tool calls, commands, approvals, errors, and outcomes can be reconstructed.

Unclear handoffs

Define ownership and data boundaries when a primary agent delegates to sub-agents or connected systems.

Choose the engagement that matches the decision in front of you.

AIM AgentGuard can begin with one of these bounded formats. Scope, supported systems, evidence access, review frequency, and limitations are confirmed before work begins. Pricing is provided only after scope.

AI Agent Security Baseline

  • Agent and sub-agent inventory
  • Ownership, tool, permission, and credential review
  • Approval and logging-gap analysis
  • Prioritized remediation plan

Assessment details

AI Agent Activity Audit

  • Review supported agent records
  • Reconstruct selected sessions
  • Redacted command, file, tool, and destination timeline
  • Limitations and confidence levels

Audit details

Secure Agent Pilot

  • One bounded business use case
  • Approved tools and least-privilege access
  • Human approval points and controlled testing
  • Rollback and shutdown plan

Pilot details

Multi-Agent Governance Review

  • Agent owners and relationships
  • Handoff and shared-memory boundaries
  • Tool and credential separation
  • Escalation and emergency shutdown process

Governance details

Managed Agent Monitoring Pilot

  • Limited, monitor-only pilot
  • Named supported agents and endpoints
  • Agreed review frequency
  • Findings and governance reporting

Monitoring details

How the engagement works

Define the boundary

Name the agents, owners, endpoints, business use case, evidence sources, and decisions the review must support.

Review safely

Use read-only discovery where possible, minimize sensitive evidence, and document coverage gaps before drawing conclusions.

Prioritize controls

Connect each finding to permissions, approvals, logging, testing, ownership, or shutdown changes.

Hand off a usable plan

Deliver a redacted summary, implementation priorities, accountable owners, and decisions requiring leadership approval.

Give every agent the minimum authority needed for the approved task.

Least privilege

Separate read access from write access, narrow tools and destinations, use task-specific credentials, and remove unused permissions.

Human approval

Keep people in control of consequential messages, transactions, code changes, record updates, and access changes.

Evidence before conclusions

State what records were available, what was unsupported, how confident the review is, and what still needs investigation.

AI agent security FAQ

What is AIM AgentGuard?

AIM AgentGuard is AI Impact Maine’s managed AI-agent security, monitoring, activity-auditing, and governance service. It reviews approved agent environments and produces practical control, documentation, and remediation guidance.

What agent activity can be reviewed?

Depending on the supported agent, hooks, integrations, and available logs, a review may cover commands, tools, files, network destinations, approvals, errors, agent and sub-agent relationships, and selected session timelines.

Can AIM AgentGuard block an AI agent action?

Monitor-only operation does not block actions. Optional enforcement may be possible on supported surfaces only after controlled testing, documented rollback procedures, and explicit client approval.

Does AIM AgentGuard replace endpoint or network security?

No. AIM AgentGuard complements but does not replace endpoint protection, identity security, email security, data loss prevention, network security, backups, legal or compliance advice, or incident-response planning.

Does AIM AgentGuard work with every AI agent?

No. Coverage depends on the selected agent, operating surface, supported hooks or integrations, and available logs. Historical reconstruction may be incomplete, and exact coverage is confirmed before work begins.

Is Numbat an AI Impact Maine product?

No. Numbat is an Apache-2.0 open-source project developed by Perplexity. AI Impact Maine may use it when technically suitable and is not affiliated with, endorsed by, or certified by Perplexity.

Start with the agent, access, and decision that matter most.

Tell us what the agent can do today and what you need to decide next. We will confirm whether AIM AgentGuard, an assessment, an activity audit, a governance review, or a bounded pilot is the right fit.