What problem does it solve?
SOSA Governor centralizes on-demand governance, compliance checks, and reporting for autonomous agents and plugin tool usage to reduce unnoticed high-impact actions, untracked token spend, and misclassified tool trust that can lead to security incidents.
Core Features & Use Cases
- Audit Reporting: Summarizes today's audit log with totals, impact-level breakdowns, denied actions, most active tools, and sessions with the most activity.
- Trust Score Management: Reads and displays tool trust scores, explains the trust formula, and resets or updates scores to control auto-approval behavior.
- Impact Registry & Reclassification: Shows high/medium/low classifications from the impact registry and enables safe reclassification with immediate effect.
- Token Budgeting: Compares configured budgets to actual usage and flags categories approaching limits.
- Compliance & Security Checks: Evaluates SOSA compliance level, verifies gating hooks and plan-act-verify loops, and performs grep-based scans for potential hardcoded secrets and suspicious audit patterns.
- Use Case: Ask for "run SOSA audit" to get a concise daily governance report, trust-score snapshot, and security findings.
Quick Start
Run a SOSA audit for today, show trust scores for all tools, and flag any security issues found in the logs.