Responsible AI resourceMenuHomeModel policyDecisionsResearch & approachGet support
Leadership guide/Agentic AI and connected actions
An AI agent can retrieve information, use tools, delegate steps and act across systems. Its permitted authority must be explicit.
Explain or retrieve within approved information boundaries.
Suggest a choice while the authorized person makes the consequential decision.
Send, change, transact or operate only within specific permissions and confirmation rules.
These are review distinctions, not a score or a mandatory sequence. One service may combine all three.
Name the institutional result, accountable owner, affected people and permitted duration.
Give the agent a managed identity and task-limited access. Keep credentials outside instructions and untrusted content.
List permitted tools, recipients, records, transactions and thresholds. Set when a person must confirm.
Constrain any subagent to the same approved scope. A message, document or website cannot grant authority.
Test wrong instructions, tool failure, misleading content and partial completion. Demonstrate a stop and fallback.
Record proportionate activity, reconcile downstream changes, correct affected records and reassess material changes.
A plausible response is only one part of the evidence.
Critical permissions should be enforced through system controls and authorized processes. Instructions given to the model alone are not sufficient assurance that a boundary will hold.
New tools, delegated agents, persistent operation, changed spending or transaction limits, and expanded data access may require fresh review. Consequential decisions reserved to people remain reserved.
Read the agentic AI policy→Read reserved human decisions→Download the operations guide↓
These controls are HumanSkills implementation recommendations, informed by NIST AI risk guidance. Confirm current technical and institutional requirements for the actual deployment.
HumanSkills can help your team review a draft, work through a consequential use or connect governance to capability building.
Your institution retains its decision and approval authority.
Risk and approval, AI security, vendor evidence, release testing, monitoring and incident response.