Control areas · Action control
AI Agent Tool Call Authorisation & Action Controls
Define permitted actions, resource boundaries and approvals outside the model.
Design and verification
Authorise the caller
Validate the actual caller identity and its permission for the resource, rather than trusting model-supplied labels.
Validate arguments
Check destinations, amounts, targets and commands at the execution boundary.
Handle failure safely
Specify rejection, escalation and recovery for unavailable policy services or invalid approvals.
Example
An agent requests a bulk export to an external destination. A control can reject the call because the destination is outside the allowed set, even if the model believes it is helping.
Engineering scope
These are control design requirements. Implementation, supported versions and evidence mechanisms are selected and verified for the customer environment. See Guardrail Engineering.
Start with a clear scope
Tell us which systems, actions and review requirements are in scope. We will discuss the work, responsibilities and deliverables before you commit.