01 · Mission
Make what an agent can do, and what it was allowed to do, a written thing.
OWASP Agent Behaviour Policies is an open, vendor-neutral method and a set of machine-readable artefacts for writing down, for one AI agent in one deployment, everything it can do, what it was authorised to do, the gap between the two, and what actually stands in the way.Proposed one-paragraph summary, for the application form
An agent is deployed with a credential, a set of tools and a place to run. Together those decide what it can do, and almost nobody has written that down. The people who deployed it know what they asked it to do, and that is usually written down nowhere either. The project gives both a shape: a list of capabilities in a shared grammar, a mandate in the deployer’s words, a gap derived from the two by a build anybody can rerun, and for every row the barrier that stands between the agent and the capability, with the evidence for it.
It describes and it does not judge. An Agent Behaviour Policy (ABP) carries no score, rating, level or verdict. The same ABP is harmless in one deployment and dangerous in another, and nothing in the document changed; the deployment did. Anything that scores is a separate thing built on top, by whoever wants to build it.