セキュリティエンジニア向けセットアップ
適用面: SDK とゲートウェイ(組織全体) 対応モード: Hosted Hybrid Local プラン: Free Solo Teams
対象読者
外部に出ていくものに責任を持つ方が対象です。
英語の原文 -- 翻訳は技術レビュー待ちです
AI tools are a new egress path, and you need deterministic prevention on enforcing surfaces, explicit coverage on every event, and a complete audit trail.
通常統制したい対象
英語の原文 -- 翻訳は技術レビュー待ちです
- Secret and PII egress. API keys, tokens, SSNs, and card numbers must never leave in a tool call or prompt.
- SDK、ゲートウェイ、コーディングアシスタント間で共有するポリシー。 適用はホストから推測されるのではなく、イベントごとに宣言されます。
英語の原文 -- 翻訳は技術レビュー待ちです
- Evidence. A durable, queryable trail of every decision that distinguishes “did not run” from “ran and found nothing.”
インストールする適用面
1つのポリシーを作成し、管理下のアプリでは SDK を、管理できないアプリの前段にはゲートウェイを使います。どちらも、組み込みの DLP パターン(AWS キー、GitHub トークン、SSN、カード番号など)に対してツール引数を自動的にスキャンします。ブロックされた場合、その呼び出しは拒否されます。Claude Code と Gemini CLI 上の Python SDK フックでは、代わりに一致した部分をその場でマスクして、呼び出しを続行させることもできます。書き換えたツール入力を受け付けられないコーディングエージェント側の適用面(Cursor、Kiro、Codex CLI、Antigravity)では、マスクルールは 代わりに拒否になります。ゲートウェイはリクエスト側とレスポンス側の両方でマスクできますが、デフォルトではどちらも行わず、検出のみを行います。切り替え方法はゲートウェイを参照してください。
pip install controlzero
スターターポリシー
通常の LLM とツールの利用は許可しつつ、DLP ルールでシークレットや PII の外部流出をブロックします。DLP の block は本来なら許可されるはずの判定を上書きするため、それ以外は許可寄りのポリシーでも、漏えいを止められます。
version: '1'
settings:
default_action: allow
default_on_missing: deny
default_on_tamper: quarantine
rules:
- id: allow-llm
allow: 'llm:generate'
reason: 'LLM use is permitted; DLP below stops leaks regardless.'
dlp_rules:
- id: block-internal-codes
pattern: 'PROJ-[A-Z]{3}-\d{6}'
category: custom
action: block
reason: 'Internal project codes must not leave the agent.'
英語の原文 -- 翻訳は技術レビュー待ちです
Built-in DLP patterns are always active; the rule above adds a custom one.
ダッシュボードでより広範な DLP ルールセットを構築するには、DLP ルールを設定するを参照してください。
確認できる内容
- DLP のブロックは、
decision: denyとDLP_BLOCKEDの理由コードとともに監査ログに記録され、どのパターンがどの呼び出しで発火したかが正確に分かります。 - 各行には、そのイベントのカバレッジが宣言されています。機能マトリクスは SDK 自身の機能宣言から導出されます。ご利用の環境向けに書き出すには
controlzero coverage --jsonを実行してください(引数なしのcontrolzero coverageは、ホストごとの短い概要だけを出力します)。
英語の原文 -- 翻訳は技術レビュー待ちです
- Each plan defines an audit log retention window -- 7 days on Free, 90 days on Solo, and 365 days on Teams -- which is plan policy and is not applied yet (see the note below: retention is an organization setting that defaults to 30 days today). Query, filter, and export the logs for reviews.
- 最初に監視のみで組織全体に展開すると、ブロックを始める前に、実際の外部流出の試みを計測できます。
英語の原文 -- 翻訳は技術レビュー待ちです
Automatic deletion of audit records at the end of the window is not currently running on the production audit store, so audit records are kept longer than the window. Deletion will be switched on only after dated notice to affected organizations. When tiered audit retention takes effect, Free organizations created before then keep their existing 30-day window unless an owner changes it, and an owner can set a shorter window.
次のステップ
- シークレットと PII の外部流出をブロックする -- 外部流出に対する標準的なレシピです。
- DLP ルールを設定する -- 検出パターンを作成して調整します。
- DLP カバレッジ -- 組み込みのパターンセットとカスタム正規表現。
- コンプライアンスレポート -- 監査証跡をレポートにします。