Configure AI agent containment

  • Release version: Zurich
  • Updated July 21, 2026
  • 1 minute to read
  • Connect identity providers and hyperscalers to ServiceNow to let you contain and enforce guardrails for AI assets at runtime using kill switch protocol.

    Before you begin

    Role required: AI steward [sn_ai_governance_ai_steward]

    About this task

    To deactivate or reinstate an AI agent using kill switch protocol, you must have:
    • A connection between ServiceNow and each hyperscaler that hosts governed AI assets. These connectors are supported:
      • AWS Bedrock
      • AWS Bedrock Agent Core
      • GCP Vertex AI (agents with unique identities only)
      • ServiceNow Agents
    • A connection between ServiceNow and an identity provider is optional. Okta is supported.

    Procedure

    1. In AI Control Tower, navigate to Settings > Integrations > Connectors > Security.
    2. Select the connector from the Available connectors view and follow the guided setup wizard.
      For more information, see Configuring security connections.
    3. If you want to manage only ServiceNow AI agents, select ServiceNow Agents from the Established connectors view and follow the guided setup wizard.
    4. After you set up connectors, navigate to the Security tab and refresh the page.

    Result

    You can now deactivate and reinstate AI agents using kill switch protocol. For more information, see Manage AI agents using kill switch protocol.