Control Packs · AUT-005 · v1.0.0
Work That Should Have Happened
Say when automated work is expected, and raise a signal when it does not happen -- because a job that stops running produces no error to notice.
Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.
What this safeguard addresses
State when each piece of automated work is expected to happen, detect its absence rather than only its failure, and route that absence to the same place a failure would go.
- Scheduled work stops happening and nothing says soA job, worker or sync stops being triggered. No run means no error, no failed count and no exception, so every existing alarm stays quiet while the work silently stops.
Versioned applicability rule
{
"any": [
{
"characteristic": "CONSEQUENTIAL_ACTION",
"equals": true
},
{
"characteristic": "TOOL_ACCESS",
"equals": true
},
{
"characteristic": "EXTERNAL_DEPENDENCY",
"equals": true
}
]
}Decisions for the project owner
Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.
- Which work runs on a schedule or a trigger, and how late is too late for each?Detecting absence needs an expectation to compare against. "Nightly" is not enough on its own — the useful answer is how long the silence can last before someone should be told.AUT-005-Q1 · scope
- What should happen when expected work has not run in time?A missed run and a failed run often need different responses. Running a skipped job late can be worse than not running it, depending on what it does.AUT-005-Q2 · choice
Requirements for the coding agent
- AUT-005-R1Record when each piece of scheduled or triggered work is expected and the confirmed lateness that counts as missing, and emit a signal derived from the absence of a run rather than from a failure inside one.
- AUT-005-R2Implement the confirmed response to work that did not run in time, route it to the same recipient a failure would reach, and make catching up a decision rather than an automatic consequence.
Tests and evidence to retain
- MISSED_RUN_DETECTION_TESTStop the trigger entirely, advance past the confirmed lateness, and verify a signal is raised from the absence of a run with no error having occurred.
- MISSED_RUN_RESPONSE_TESTVerify the confirmed response to a missed window runs, and that a caught-up run is bounded to the confirmed behaviour rather than replaying every missed window at once.
- configuration_or_policy
- implementation_location
- test_result
- operational_procedure
Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.
Related guidance
- SI-4 · System MonitoringNIST_SP_800_53_5_2_0 · partially addressesDetecting that expected work did not occur addresses one monitoring condition. It does not cover intrusion detection, network monitoring, or the wider monitoring programme.
- CA-7 · Continuous MonitoringNIST_SP_800_53_5_2_0 · partially addressesStating an expectation and comparing reality against it is a narrow instance of continuous monitoring; it does not constitute a monitoring strategy or assessment programme.
Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.
- National Institute of Standards and Technology — Security and Privacy Controls for Information Systems and OrganizationsGUIDANCE_NIST_SP_800_53_5_2_0
- Amazon Web Services Builders' Library — Timeouts, retries, and backoff with jitterGUIDANCE_RELIABILITY
- National Institute of Standards and Technology — Artificial Intelligence Risk Management FrameworkGUIDANCE_AUTOMATION