以下の一部の詳細セクションは英語です。本文の言語を明示しており、完全な日本語訳とはしていません。
適用範囲
Agent Guard supervises browser-visible activity performed by AI agents on websites a user explicitly authorizes. It identifies supported high-risk actions and sensitive-data categories, compares actions with user-confirmed intent and deterministic policy, requests approval or blocks supported actions, and keeps a redacted local audit trail.
Agent Guard is not a general chatbot, password manager, tracker blocker, endpoint DLP system, or guarantee against every prompt-injection attack.
処理する情報
On authorized sites, Agent Guard may transiently process browser-visible field values or metadata to classify personally identifiable information, health information, financial or payment information, authentication information, precise-location fields, and other sensitive categories.
It may inspect bounded page text on authorized webmail, messaging, collaboration, or other pages for prompt-injection signals. It may also process authorized site origin, redacted URL, timestamps, browser-visible clicks, input attempts, submissions, sends, uploads, downloads, navigation, approvals, settings, field labels, target descriptions, links, and destination origins.
Agent Guard does not intentionally perform keystroke logging or retain typed text as a transcript.
データ最小化
Raw form values and bounded page text are inspected transiently in the page and are not intentionally stored in the audit model. Persistent records use sensitive-data category indicators, redacted labels, redacted URLs, origin names, amount buckets, action metadata, policy decisions, and other minimized context.
A page-local masked preview can be shown during approval but is not sent to the extension service worker or included in exports. Agent Guard does not intentionally read or retain file contents, Cookie values, browser-storage values, full request bodies, or private keys.
Agent Guard stores categories and decisions—not a copy of the user's conversation or form contents.
情報の用途
Information is used only to show Guard Health and session status; evaluate intent contracts, risk budgets, profiles, and local policy; pause, approve, block, or replay supported actions; build local data-lineage and prompt-risk associations; compare local sessions; generate user-requested exports; link optional cross-tab workflows; and install optional temporary network-quarantine rules.
Policy decisions are deterministic in the current release. Agent Guard does not send prompts or page content to a developer-operated AI service.
タスクテンプレートと合成テスト
3種類のテンプレートは拡張機能内で明示的に確認してから現在のオリジンに適用され、1時間で期限切れになります。意図を置換し、予算をリセットして一時許可を消去します。承認待ち・実行中の動作やページ変更時には危険な置換を拒否します。
管理ポリシーとカスタム規則は引き続き適用されます。合成テストはポリシーエンジンのみを実行し、実ネットワーク送信や動作の再実行は行いません。完全な防御の証明ではありません。
タスクの期限と許可記録
期限を確認し、明示的な確認後にタスクを終了して許可を消去し、Panic Lockを有効にできます。すでに送信された動作は取り消せません。
ローカル監査は最小化された許可・予算情報を含む場合があります。予算は許可の試行を保守的に計上し、送信失敗時に自動返還しません。worker再起動時に実行中の動作を自動再実行しません。
診断センター
診断は利用者の操作時に生成・出力されます。バージョン、状態、集計値とローカル設定を含み、ホスト名、URL、タブや文書ID、ページ本文、監査内容を含みません。予算は承認の試行を保守的に計上し、送信失敗時に自動返還しません。テレメトリや外部AIは追加していません。
任意のローカルブリッジ
Agent Guard can connect locally to the separately installed SiteEgress extension. Both local bridge settings must be enabled before a summary is exchanged.
Agent Guard can receive minimized SiteEgress privacy context for an origin or requested destination, and can return minimized action, destination-category, policy-outcome, and evidence metadata. Sensitive values and raw IP addresses are excluded.
SiteEgress evidence is advisory context. It cannot create an Agent Guard approval, grant, policy decision, or enforcement result.
Exact published extension IDs, sender validation, schema projection, collection limits, and dual opt-in constrain the bridge.
ローカル保存と保持
Live sessions are stored in chrome.storage.session. Settings, user rules, imported policy, and optional bounded history are stored in chrome.storage.local. Administrator policy may be read from chrome.storage.managed.
Users can disable history, set available retention limits, clear local data, remove rules, revoke grants, and uninstall the extension.
送信・販売・共有
Agent Guard has no developer-operated analytics, telemetry endpoint, cloud account, remote AI service or remote executable rule feed. It does not automatically upload audit reports, browsing activity, form values, settings or local history to a developer server.
If enabled in both products, the optional local bridge exchanges only the minimized metadata listed in its section. Audit exports are created on your device; you decide whether to share them. Agent Guard does not sell user data or use it for advertising, creditworthiness or lending.
権限とサイトへのアクセス
Default API permissions are activeTab, scripting, sidePanel, and storage. HTTP and HTTPS site access is optional and requested per origin only after the user chooses to authorize that site.
Optional permissions may include notifications for a generic approval notice, webNavigation for local cross-tab workflow linkage and document lifecycle, and declarativeNetRequestWithHostAccess for temporary tab-scoped destination quarantine without reading request bodies. Users can revoke site access and optional permissions.
セキュリティと限界
Agent Guard uses bounded messages and collections, sender and document binding, redaction, export sanitization, packaged executable code, and explicit coverage reporting.
No software can identify every agent, detect every prompt injection, observe server-to-server processing, stop synchronous channels that cannot wait for approval, or guarantee complete security. Page-derived evidence is untrusted and can be influenced by the website.
連絡先とポリシー変更
Users may revoke site access and optional permissions, disable Deep Probe and local history, clear history or all extension data, remove rules, reject actions, use Panic Lock, uninstall the extension, and delete exported files.
Privacy questions can be sent to agentguard@siteegress.com or privacy@siteegress.com. Material changes will be reflected in this policy before or when the new processing becomes available.
このポリシーは拡張機能が対象です。siteegress.com のアクセス解析とは別であり、拡張機能の監査データはサイトの解析サービスへ送信されません。
公式サイトのアクセス解析について