Egress, routing, and response controls
Make external access, endpoint choice, response inspection, and failure behavior explicit and testable.
Make egress explicit
Define which identities, workloads, data classes, purposes, endpoints, regions, models, tools, protocols, and time windows may leave the controlled boundary. Network reachability is not authorization; policy must bind the request context to an approved destination.
Route policy
Route using authoritative identity, classification, workload, health, capacity, and approval inputs. Pin destinations to approved identities and contracts. Prevent DNS, redirects, alternate protocols, direct service endpoints, administrative paths, or retries from bypassing the route decision.
When no destination is acceptable, deny, queue, request approval, or provide a locally approved degraded result. Do not silently choose a public endpoint.
Response controls
Validate source endpoint, response structure, size, streaming, classification, policy markers, tool instructions, citations, and prohibited disclosures. Define whether redaction, blocking, truncation, warning, or escalation is safe for each application.
Verification
Test allowed and denied routes, unavailable local capacity, endpoint identity mismatch, redirect, split payload, streaming policy violation, response leakage, timeout, policy outage, evidence outage, and emergency override. Evidence should connect the initiating actor to the final destination and applied controls.