Four things a rule can do. None of them is 'allow more'.
Every call passes a checkpoint you configure. A rule can let it through, block it, hold it for a person, or trim what goes out and comes back. A rule can never hand an agent access it was not already given.
One call at a time, sorted
Same agent, same session — four different calls, four different answers.
Before the call, and after it
Blocking a bad request matters. So does catching what comes back — a read that returns more than it should is still a leak.
Enforce the AI security vendor you already bought
Govna is the enforcement point, not another scanner. Point a rule at the provider your security team already chose — or at your own signed HTTPS endpoint — and its verdict decides whether the call goes out. A provider can only narrow access, and a provider that cannot answer fails closed.
Ten checks you do not have to buy
Enough to survive a first review without adding a vendor.
Where to go next
Two readers, two different next steps.