Control Packs · AUT-002 · v1.1.0

Bounded Irreversible and Bulk Action

Preview, bound, and recover from destructive or irreversible automated actions before they are released.

Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.

What this safeguard addresses

Require an explicit scope, preview or dry run, bounded execution, recovery decision, and emergency stop for irreversible actions.

  • Irreversible action exceeds its confirmed boundaryAn automated or bulk operation can permanently change records or resources without a preview, bounded scope, recovery plan, or disable path.
Versioned applicability rule
{
  "any": [
    {
      "characteristic": "IRREVERSIBLE_ACTION",
      "equals": true
    },
    {
      "all": [
        {
          "characteristic": "CONSEQUENTIAL_ACTION",
          "equals": true
        },
        {
          "characteristic": "IRREVERSIBLE_ACTION",
          "equals": true
        }
      ]
    }
  ]
}

Decisions for the project owner

Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.

  • What protection is required before an irreversible action can run?The service must not infer whether preview, approval, backup, or a smaller batch is sufficient.AUT-002-Q1 · choice

Requirements for the coding agent

  • AUT-002-R1Enforce a confirmed scope, preview or dry-run path, bounded execution, recovery strategy, and emergency disable for irreversible actions.

Tests and evidence to retain

  • IRREVERSIBLE_BOUNDARY_TESTExercise preview, approval, bounded execution, duplicate, stop, and recovery behavior.
  • configuration_or_policy
  • implementation_location
  • test_result
  • operational_procedure

Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.

Related guidance

  • SI-17 · Fail-Safe ProceduresNIST_SP_800_53_5_2_0 · partially addressesPreview, bounded execution, recovery, and disable behavior support fail-safe operation for irreversible actions; they do not establish full coverage.
  • CP-10 · System RecoveryNIST_SP_800_53_5_2_0 · partially addressesThe recovery strategy and tested restoration path address a slice of system recovery; they do not cover all contingencies.
  • SA-11 · Developer Testing and EvaluationNIST_SP_800_53_5_2_0 · partially addressesThe required boundary and recovery exercises support targeted evaluation; they are not a complete testing program.

Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.

Continue your review