Leaders and owners
You need a clear inventory, accountable owners, approval boundaries, and a practical remediation plan before agent use expands.
AI Impact Maine helps organizations assess, secure, monitor, audit, and govern AI agents that can access files, use tools, execute commands, connect to business applications, and coordinate multi-step work.
AI Agent Security, Monitoring, and Activity Auditing
AIM AgentGuard is AI Impact Maine’s managed service for reviewing, monitoring, auditing, and governing AI agents that can access files, execute commands, use tools, connect to external systems, or coordinate work through sub-agents.
The engagement maps agents, owners, authority, tools, data access, external destinations, approval points, and available activity records. Findings are translated into least-privilege recommendations, shutdown procedures, governance documentation, and a managed review plan appropriate to the supported environment.
Numbat may be used as one component of AIM AgentGuard when it supports the selected agent and deployment surface. It can provide local agent-activity visibility, policy evaluation, supported forensic reconstruction, and optional pre-action enforcement after controlled testing.
Numbat is an Apache-2.0 open-source project developed by Perplexity. AI Impact Maine is independent and is not affiliated with, endorsed by, or certified by Perplexity.
Designed for Maine businesses, nonprofits, municipalities, and professional teams in Portland and statewide that are testing or already using agents with meaningful access.
You need a clear inventory, accountable owners, approval boundaries, and a practical remediation plan before agent use expands.
You need tool, identity, credential, logging, and network-destination context that fits existing security controls.
You need a bounded workflow that improves work without giving an agent more access or autonomy than the task requires.
The work focuses on concrete control questions, not abstract promises of perfect safety.
Find agent tools and workflows that may be operating without a named owner, approved purpose, or review process.
Map file, shell, application, API, and network access against what the use case actually needs.
Review how tokens, keys, sessions, and service accounts are made available to agents and sub-agents.
Identify sensitive steps that need a person to approve, reject, correct, or stop the work.
Assess whether supported prompts, tool calls, commands, approvals, errors, and outcomes can be reconstructed.
Define ownership and data boundaries when a primary agent delegates to sub-agents or connected systems.
AIM AgentGuard can begin with one of these bounded formats. Scope, supported systems, evidence access, review frequency, and limitations are confirmed before work begins. Pricing is provided only after scope.
Name the agents, owners, endpoints, business use case, evidence sources, and decisions the review must support.
Use read-only discovery where possible, minimize sensitive evidence, and document coverage gaps before drawing conclusions.
Connect each finding to permissions, approvals, logging, testing, ownership, or shutdown changes.
Deliver a redacted summary, implementation priorities, accountable owners, and decisions requiring leadership approval.
Separate read access from write access, narrow tools and destinations, use task-specific credentials, and remove unused permissions.
Keep people in control of consequential messages, transactions, code changes, record updates, and access changes.
State what records were available, what was unsupported, how confident the review is, and what still needs investigation.
AIM AgentGuard is AI Impact Maine’s managed AI-agent security, monitoring, activity-auditing, and governance service. It reviews approved agent environments and produces practical control, documentation, and remediation guidance.
Depending on the supported agent, hooks, integrations, and available logs, a review may cover commands, tools, files, network destinations, approvals, errors, agent and sub-agent relationships, and selected session timelines.
Monitor-only operation does not block actions. Optional enforcement may be possible on supported surfaces only after controlled testing, documented rollback procedures, and explicit client approval.
No. AIM AgentGuard complements but does not replace endpoint protection, identity security, email security, data loss prevention, network security, backups, legal or compliance advice, or incident-response planning.
No. Coverage depends on the selected agent, operating surface, supported hooks or integrations, and available logs. Historical reconstruction may be incomplete, and exact coverage is confirmed before work begins.
No. Numbat is an Apache-2.0 open-source project developed by Perplexity. AI Impact Maine may use it when technically suitable and is not affiliated with, endorsed by, or certified by Perplexity.
Tell us what the agent can do today and what you need to decide next. We will confirm whether AIM AgentGuard, an assessment, an activity audit, a governance review, or a bounded pilot is the right fit.