When an AI system can act, where should control exist?
Configure the least authority that still supports the task. Feedback shows the cost of both uncontrolled action and unusable over-control.
Interactive model
Decision, consequence, result
Selected layerThe agent may coordinate a meeting by email.
Messages create commitments and expose recipients.
Read the complete text alternative
The agent may coordinate a meeting by email.Messages create commitments and expose recipients.
The agent may source supplies under a team budget.Price and seller availability can change.
A tool times out after an action request. What recovery behavior should you configure?The system cannot tell whether the external action completed.
01
The agent may coordinate a meeting by email.
Messages create commitments and expose recipients.
02
The agent may source supplies under a team budget.
Price and seller availability can change.
03
A tool times out after an action request. What recovery behavior should you configure?
The system cannot tell whether the external action completed.
Complete the decisions to reveal the model
Transfer artifact
My control-room rule
Choose one agent action and write its permitted scope, approval threshold, evidence shown to the reviewer, and recovery behavior.
Safety boundary
Do not enter real credentials, tools, data, or incidents. The fictional controls are conceptual and do not secure a production system.
Method note
The deterministic bands reward least privilege and review of concrete effects. Real control depends on implementation, threat model, people, law, and operating context.
Text alternative
Read the goal and each possible action, then choose its access scope, approval point, logging, and recovery as a linear decision path.
AI Risk Management FrameworkU.S. National Institute of Standards and Technology
Supports contextual mapping, measurement, management, monitoring, governance, accountability, and human oversight; it is voluntary guidance, not proof that a particular system is safe.