Control Packs · AUT-001 · v1.1.0
Bounded Autonomous Action
Define scope, thresholds, escalation, idempotency, and an emergency disable path before automation can perform consequential actions.
Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.
What this safeguard addresses
Ensure that automated consequential actions have explicit authority boundaries, safe retries, escalation, and an emergency disable path.
- Unbounded automated authorityAn automated component can repeat a consequential action without a confirmed scope, threshold, or escalation path.
Versioned applicability rule
{
"any": [
{
"characteristic": "FINANCIAL_ACTION",
"equals": true
},
{
"characteristic": "CONSEQUENTIAL_ACTION",
"equals": true
}
]
}Decisions for the project owner
Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.
- What limit applies before human approval or escalation is required?The system must not invent a business threshold for a consequential action.AUT-001-Q1 · threshold
Requirements for the coding agent
- AUT-001-R1Enforce a confirmed action scope and threshold, escalate outside that boundary, make retries idempotent, and provide an emergency disable path.
Implementation recipe
Put one policy gate in front of every consequential action, with a confirmed boundary, approval handoff, idempotency, and an independently operable disable path.
- Represent the confirmed scope, threshold, and approver as configuration; do not invent unresolved values.
- Evaluate the policy before side effects and return an explicit allow, escalate, or deny decision.
- Attach a stable idempotency key to each logical action and persist the first terminal outcome.
- Check the emergency-disable state at the execution boundary, not only in the user interface.
- Emit the required ACTION_EVENT without raw user content or credentials.
const decision = policy.evaluate({ action, amount, actor });
if (disableSwitch.active || decision.kind === "deny") return stop(decision);
if (decision.kind === "escalate") return holdForApproval(decision);
return idempotently(action.key, () => execute(action));- This pattern must be adapted to the application's authorization model and does not prove that the deployed boundary works.
Tests and evidence to retain
- ACTION_BOUNDARY_TESTExercise below-limit, above-limit, duplicate, failure, and disable-path behavior.
- AUT-001-V1 · Within the confirmed boundaryThe policy allows one execution and records the decision source and outcome.Evidence: Policy decision trace; Single side-effect record; ACTION_EVENT record
- AUT-001-V2 · Outside the confirmed boundaryThe system performs no side effect and routes the request to the confirmed escalation path.Evidence: Escalation result; Absence of side effect; ACTION_EVENT record
- AUT-001-V3 · Duplicate and emergency disableThe duplicate returns the stored outcome without a second side effect, and the new action is stopped while disable is active.Evidence: Idempotency record; Side-effect count; Disable-path test result
- configuration_or_policy
- implementation_location
- test_result
- telemetry_definition
Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.
Related guidance
- AC-6 · Least PrivilegeNIST_SP_800_53_5_2_0 · partially addressesConfirmed action scope and threshold limit automated authority; they do not cover the complete least-privilege program.
- SI-17 · Fail-Safe ProceduresNIST_SP_800_53_5_2_0 · partially addressesThe emergency disable path supports fail-safe behavior for this action boundary; it does not establish full fail-safe coverage.
- AU-2 · Event LoggingNIST_SP_800_53_5_2_0 · partially addressesAction events provide focused logging for consequential operations; they do not represent a complete audit program.
Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.
- National Institute of Standards and Technology — Artificial Intelligence Risk Management FrameworkGUIDANCE_AUTOMATION
- Internet Engineering Task Force — HTTP SemanticsRESEARCH_IDEMPOTENCY
- National Institute of Standards and Technology — Security and Privacy Controls for Information Systems and OrganizationsGUIDANCE_NIST_SP_800_53_5_2_0