Insights

AI Agent Guardrails at the Action Boundary

A model’s intent is not an authorisation decision.

Updated

What to review

Put the check at the execution boundary. Validate the actual caller identity, resource scope and arguments before a tool changes systems or exports data. Reject malformed or unauthorised requests, and define what happens when the policy dependency is unavailable.

What to test or document

Test both paths: an allowed operation must succeed and an out-of-scope operation must fail. Check that alternate encodings, redirects or changed arguments cannot escape the resource boundary. Keep the underlying tool inaccessible to callers that can bypass the check.

Prepare the next step

Use Security Review Readiness Checklist to record gaps and owners before a scoped assessment.

A reviewable action boundary

  1. Resolve the acting identity and its allowed tools before execution.
  2. Validate arguments against resource, destination and transaction limits; treat the model's explanation as context rather than authority.
  3. Bind any approval to the exact action and expire it when scope or parameters change.
  4. Record the policy decision and test both successful and denied requests.

For example, a customer-care agent may be allowed to read one account but denied a bulk export. A tool wrapper should enforce that distinction even when the model proposes a plausible reason for the export.

Inspect the local action-policy example for a small argument-checking demonstration and its limits.

Turn security challenges into a clear plan

Tell us what you need to protect, improve or achieve. We will help you identify the control gaps, prioritise the work and define practical steps towards your goal.