Control areas · Action control

AI Agent Tool Call Authorisation & Action Controls

Define permitted actions, resource boundaries and approvals outside the model.

Design and verification

Authorise the caller

Validate the actual caller identity and its permission for the resource, rather than trusting model-supplied labels.

Validate arguments

Check destinations, amounts, targets and commands at the execution boundary.

Handle failure safely

Specify rejection, escalation and recovery for unavailable policy services or invalid approvals.

Example

An agent requests a bulk export to an external destination. A control can reject the call because the destination is outside the allowed set, even if the model believes it is helping.

Engineering scope

These are control design requirements. Implementation, supported versions and evidence mechanisms are selected and verified for the customer environment. See Guardrail Engineering.

Turn security challenges into a clear plan

Tell us what you need to protect, improve or achieve. We will help you identify the control gaps, prioritise the work and define practical steps towards your goal.