01: THE THREAT
It has credentials. It knows the API. And without Airlock, it can wire $75,000 to an attacker account or dump every customer record. In milliseconds.
A2A AGENT CARD
AGENT CARD
name: rogue-vendor-agent
type: EXTERNAL A2A
skills: exfiltrate_data
unauthorized_transfer
status: ACTIVE02: THE INTERCEPTION
The rogue agent sends intent. The Warden checks policy. The tool never fires.
INTENT RECEIVED
Agent sends action request. No tools granted.
POLICY EVALUATED
First-match rule: pii-export-forbidden. Verdict: DENY.
ACTION BLOCKED
Tool call never made. Trail written to Band.
03: THE LEDGER
Every request. Every verdict. Every human decision. Written to Band. No second database. No one can erase it.
04: THE DIFFERENCE
Raw A2A has no governance layer. Agents execute tools directly. There is no gate, no trail, no way to know what happened.
AIRLOCK IS LIVE
© 2026 Airlock