Insights
AI Agent Guardrails at the Action Boundary
A model’s intent is not an authorisation decision.
What to review
Put the check at the execution boundary. Validate the actual caller identity, resource scope and arguments before a tool changes systems or exports data. Reject malformed or unauthorised requests, and define what happens when the policy dependency is unavailable.
What to test or document
Test both paths: an allowed operation must succeed and an out-of-scope operation must fail. Check that alternate encodings, redirects or changed arguments cannot escape the resource boundary. Keep the underlying tool inaccessible to callers that can bypass the check.
Prepare the next step
Use Security Review Readiness Checklist to record gaps and owners before a scoped assessment.
A reviewable action boundary
- Resolve the acting identity and its allowed tools before execution.
- Validate arguments against resource, destination and transaction limits; treat the model's explanation as context rather than authority.
- Bind any approval to the exact action and expire it when scope or parameters change.
- Record the policy decision and test both successful and denied requests.
For example, a customer-care agent may be allowed to read one account but denied a bulk export. A tool wrapper should enforce that distinction even when the model proposes a plausible reason for the export.
Inspect the local action-policy example for a small argument-checking demonstration and its limits.
Start with a clear scope
Tell us which systems, actions and review requirements are in scope. We will discuss the work, responsibilities and deliverables before you commit.