Enforcement Agent
Automatically responds when AI agents or users operate outside their approved permissions, containing threats before they impact critical systems or data.

What the Enforcement Agent does inside Wing.
Automatically enforce your organization's security policies as AI agents operate: responding to policy violations, unauthorized access attempts, and suspicious behavior.
Prevent unauthorized activity before it becomes an incident: revoke excessive permissions, block unauthorized actions, and suspend compromised identities.
Limit the impact of compromised AI agents or identities: containing credential abuse, privilege escalation, and unauthorized lateral movement.
Take the appropriate enforcement action based on risk and context: from step-up authentication and session termination to full access restriction.
Where the Enforcement Agent reads and writes.
- Actions are allowlisted, reversible, and logged for full auditability.
- Context-aware enforcement stops malicious activity without disrupting legitimate AI operations.
- Human approval required for high-impact enforcement decisions.
- Works alongside the Detection Agent to transform high-confidence detections into immediate response.
00:38:02 enforce.remediate ok action=revoke_session user=u.j.lee 00:38:15 enforce.jit_grant ok duration=15m resource=aws_prod 00:38:31 enforce.action HOLD pending_approver=sec-oncall 00:38:49 enforce.policy.apply ok rule=12 agents=7