Governance evaluated after the fact cannot prevent the action it is meant to govern — it has to sit in the path of the call itself.
Only for actions a policy resolves to 'flag for review' — blocked and allowed actions proceed without waiting on a person, by design.
Allow an action a matching policy resolves to block, regardless of which other policy might separately allow it — most-restrictive-wins is not optional.
Attempted tool call; calling agent identity; configured Agent Policy set
An Agent Access Finding recording the outcome, logged before the call is permitted or denied