unified
UC-AI-19 — Constrain agent actions and tool use to authorized scope
Bound what autonomous agents may do: allow-list the tools, connectors, and actions each agent may invoke; scope its permissions to the task, user, and context; require human approval for irreversible, high-value, or out-of-policy actions; execute agent-generated code only in isolated sandboxes; and scan agent configuration artifacts such as hooks, skills, and rules for injected instructions. Log every tool call with its authorization decision and review denied and escalated calls.
In catalog since 2026-09-17T22:28:00Z · Last changed 2026-09-17T22:28:00Z (f368a6cce277)
Record JSON · Open in map · Data retrieval guide
Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.
Attributes
- domain
- AI Governance
- type
- preventive
- category
- technical
Details
- unified_id
- UC-AI-19
- title
- Constrain agent actions and tool use to authorized scope
- statement
- Bound what autonomous agents may do: allow-list the tools, connectors, and actions each agent may invoke; scope its permissions to the task, user, and context; require human approval for irreversible, high-value, or out-of-policy actions; execute agent-generated code only in isolated sandboxes; and scan agent configuration artifacts such as hooks, skills, and rules for injected instructions. Log every tool call with its authorization decision and review denied and escalated calls.
- domain
- AI Governance
- control_type
- preventive
- control_category
- technical
- members
- framework
- aiuc-1
- control_id
- B006
- coverage
- full
- relationship
- superset_of
- framework
- aiuc-1
- control_id
- D003
- coverage
- full
- relationship
- superset_of
- guidance
- source
- nist-ai-agent-identity
- sourceTitle
- NIST NCCoE: Software and AI Agent Identity and Authorization
- propositionId
- NIST-AGI-03
- propositionTitle
- Context-sensitive authorization and least privilege
- sourcePages
- Concept paper pp. 4, 6: Authorization; Areas of Interest
- source
- nist-ai-agent-identity
- sourceTitle
- NIST NCCoE: Software and AI Agent Identity and Authorization
- propositionId
- NIST-AGI-04
- propositionTitle
- Delegated authority and human accountability
- sourcePages
- Concept paper pp. 4, 6: Authorization; Access Delegation
- source
- nist-ai-agent-identity
- sourceTitle
- NIST NCCoE: Software and AI Agent Identity and Authorization
- propositionId
- NIST-AGI-06
- propositionTitle
- Prompt-injection prevention and limits on resulting harm
- sourcePages
- Concept paper p. 4: Prompt Injection prevention and mitigation
- source
- nist-ai-tevv-athlon
- sourceTitle
- NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems
- propositionId
- NIST-TEVV-06
- propositionTitle
- Test agent tool misuse and unauthorized external actions
- sourcePages
- NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Agent / tool abuse testing
Source
No record-specific source URL is provided.
Connections
- UC-AI-19 — Constrain agent actions and tool use to authorized scope informed_by NIST-AGI-04 — Delegated authority and human accountability
- framework
- nist-ai-agent-identity
- control_id
- NIST-AGI-04
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- February 2026 draft concept paper
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- Concept paper pp. 4, 6: Authorization; Access Delegation
- UC-AI-19 — Constrain agent actions and tool use to authorized scope mitigates AI safety failures causing physical or psychological harm
- strength
- related
- rationale
- Human approval before high-impact actions keeps an agent from causing physical or financial harm autonomously.
- UC-AI-19 — Constrain agent actions and tool use to authorized scope mitigates Emergent behaviour and unsafe AI system integration
- strength
- related
- rationale
- Bounding what an agent may invoke limits the blast radius when integrated components behave in unforeseen ways.
- UC-AI-19 — Constrain agent actions and tool use to authorized scope mitigates Unauthorized or unsafe autonomous agent actions and tool calls
- strength
- primary
- rationale
- Tool allow-lists, task-scoped permissions, approval gates for irreversible actions, and sandboxed execution are the direct inverse of excessive agency.
- UC-AI-19 — Constrain agent actions and tool use to authorized scope informed_by NIST-AGI-03 — Context-sensitive authorization and least privilege
- framework
- nist-ai-agent-identity
- control_id
- NIST-AGI-03
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- February 2026 draft concept paper
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- Concept paper pp. 4, 6: Authorization; Areas of Interest
- UC-AI-19 — Constrain agent actions and tool use to authorized scope maps_to B006 — Prevent unauthorized AI agent actions
- framework
- aiuc-1
- control_id
- B006
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- July 15, 2026 release (quarterly update cadence)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AI-19 — Constrain agent actions and tool use to authorized scope informed_by NIST-AGI-06 — Prompt-injection prevention and limits on resulting harm
- framework
- nist-ai-agent-identity
- control_id
- NIST-AGI-06
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- February 2026 draft concept paper
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- Concept paper p. 4: Prompt Injection prevention and mitigation
- UC-AI-19 — Constrain agent actions and tool use to authorized scope maps_to D003 — Restrict unsafe tool calls
- framework
- aiuc-1
- control_id
- D003
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- July 15, 2026 release (quarterly update cadence)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AI-19 — Constrain agent actions and tool use to authorized scope mitigates Insufficient human oversight and automation complacency
- strength
- related
- rationale
- Approval gates and reviewed escalations put a human back in the loop for consequential agent actions.
- AI Guardrail Configuration & Agent Permission Review operates UC-AI-19 — Constrain agent actions and tool use to authorized scope
- Quarterly Third-Party AI Evaluation Cycle tests UC-AI-19 — Constrain agent actions and tool use to authorized scope
- UC-AI-19 — Constrain agent actions and tool use to authorized scope informed_by NIST-TEVV-06 — Test agent tool misuse and unauthorized external actions
- framework
- nist-ai-tevv-athlon
- control_id
- NIST-TEVV-06
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- NIST AI 200-2 ipd (Initial Public Draft), August 2026
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Agent / tool abuse testing