{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"AI Governance","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AI-19","description":"Bound what autonomous agents may do: allow-list the tools, connectors, and actions each agent may invoke; scope its permissions to the task, user, and context; require human approval for irreversible, high-value, or out-of-policy actions; execute agent-generated code only in isolated sandboxes; and scan agent configuration artifacts such as hooks, skills, and rules for injected instructions. Log every tool call with its authorization decision and review denied and escalated calls.","details":{"control_category":"technical","control_type":"preventive","domain":"AI Governance","guidance":[{"propositionId":"NIST-AGI-03","propositionTitle":"Context-sensitive authorization and least privilege","source":"nist-ai-agent-identity","sourcePages":"Concept paper pp. 4, 6: Authorization; Areas of Interest","sourceTitle":"NIST NCCoE: Software and AI Agent Identity and Authorization"},{"propositionId":"NIST-AGI-04","propositionTitle":"Delegated authority and human accountability","source":"nist-ai-agent-identity","sourcePages":"Concept paper pp. 4, 6: Authorization; Access Delegation","sourceTitle":"NIST NCCoE: Software and AI Agent Identity and Authorization"},{"propositionId":"NIST-AGI-06","propositionTitle":"Prompt-injection prevention and limits on resulting harm","source":"nist-ai-agent-identity","sourcePages":"Concept paper p. 4: Prompt Injection prevention and mitigation","sourceTitle":"NIST NCCoE: Software and AI Agent Identity and Authorization"},{"propositionId":"NIST-TEVV-06","propositionTitle":"Test agent tool misuse and unauthorized external actions","source":"nist-ai-tevv-athlon","sourcePages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Agent / tool abuse testing","sourceTitle":"NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems"}],"members":[{"control_id":"B006","coverage":"full","framework":"aiuc-1","relationship":"superset_of"},{"control_id":"D003","coverage":"full","framework":"aiuc-1","relationship":"superset_of"}],"statement":"Bound what autonomous agents may do: allow-list the tools, connectors, and actions each agent may invoke; scope its permissions to the task, user, and context; require human approval for irreversible, high-value, or out-of-policy actions; execute agent-generated code only in isolated sandboxes; and scan agent configuration artifacts such as hooks, skills, and rules for injected instructions. Log every tool call with its authorization decision and review denied and escalated calls.","title":"Constrain agent actions and tool use to authorized scope","unified_id":"UC-AI-19"},"id":"uc:UC-AI-19","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AI-19","sourceIds":["aiuc-1","nist-ai-agent-identity","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"UC-AI-19 — Constrain agent actions and tool use to authorized scope","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0133a2c1892582556aaef2836cf10b69b9c03fa90763ce4437e654f5ae874ae6","properties":{"control_id":"NIST-AGI-04","coverage":"guidance","delta":null,"framework":"nist-ai-agent-identity","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"Concept paper pp. 4, 6: Authorization; Access Delegation","source_version":"February 2026 draft concept paper"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-19-535f3660.json","sourceId":"uc:UC-AI-19","targetDetailPath":"/data/v1/records/ctrl-nist-ai-agent-identity-nist-agi-04-70a3e945.json","targetId":"ctrl:nist-ai-agent-identity:NIST-AGI-04","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0d8a8e0513e244581e4966b0a213a6921bd4968ca250b02e6bbf74c364507cef","properties":{"rationale":"Human approval before high-impact actions keeps an agent from causing physical or financial harm autonomously.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-19-535f3660.json","sourceId":"uc:UC-AI-19","targetDetailPath":"/data/v1/records/risk-ai-safety-harm-to-people-d02cb500.json","targetId":"risk:ai-safety-harm-to-people","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4264bbe574eb6d85a3b16e6bfb401e4a9ceffd042b764dc8e30a8af83eb25957","properties":{"rationale":"Bounding what an agent may invoke limits the blast radius when integrated components behave in unforeseen ways.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-19-535f3660.json","sourceId":"uc:UC-AI-19","targetDetailPath":"/data/v1/records/risk-ai-emergent-integration-risk-8490271c.json","targetId":"risk:ai-emergent-integration-risk","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:629deb63d191633ca0dbe5669e4f258edc0469168b578352a61bb274419588de","properties":{"rationale":"Tool allow-lists, task-scoped permissions, approval gates for irreversible actions, and sandboxed execution are the direct inverse of excessive agency.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-19-535f3660.json","sourceId":"uc:UC-AI-19","targetDetailPath":"/data/v1/records/risk-ai-agent-unauthorized-actions-194415b8.json","targetId":"risk:ai-agent-unauthorized-actions","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:646b3e051d76759d535f496d3e10af53505391b6086f3f8cb2e5787327ee0e11","properties":{"control_id":"NIST-AGI-03","coverage":"guidance","delta":null,"framework":"nist-ai-agent-identity","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"Concept paper pp. 4, 6: Authorization; Areas of Interest","source_version":"February 2026 draft concept paper"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-19-535f3660.json","sourceId":"uc:UC-AI-19","targetDetailPath":"/data/v1/records/ctrl-nist-ai-agent-identity-nist-agi-03-0c271eec.json","targetId":"ctrl:nist-ai-agent-identity:NIST-AGI-03","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7677aeab7f884ba8b21cc4945d4354d344a58e19089c4d325a668392b0e90983","properties":{"control_id":"B006","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-19-535f3660.json","sourceId":"uc:UC-AI-19","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-b006-2951b397.json","targetId":"ctrl:aiuc-1:B006","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:859e8227f7b855806f944d829b9ffc1e92d2c35ff28d579c6f9fac59c595da0c","properties":{"control_id":"NIST-AGI-06","coverage":"guidance","delta":null,"framework":"nist-ai-agent-identity","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"Concept paper p. 4: Prompt Injection prevention and mitigation","source_version":"February 2026 draft concept paper"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-19-535f3660.json","sourceId":"uc:UC-AI-19","targetDetailPath":"/data/v1/records/ctrl-nist-ai-agent-identity-nist-agi-06-e6b81ea1.json","targetId":"ctrl:nist-ai-agent-identity:NIST-AGI-06","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bbb58faf8b3bbc3d66ef9d7bdeb1609b34fe95674799e8fafe7397a3eb61191b","properties":{"control_id":"D003","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-19-535f3660.json","sourceId":"uc:UC-AI-19","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-d003-9f8f52f3.json","targetId":"ctrl:aiuc-1:D003","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c6544a91d9d991f1d537b87a1da443b4364e318a48c2eee236c3599a4b2d752b","properties":{"rationale":"Approval gates and reviewed escalations put a human back in the loop for consequential agent actions.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-19-535f3660.json","sourceId":"uc:UC-AI-19","targetDetailPath":"/data/v1/records/risk-ai-insufficient-human-oversight-6c4f3dfa.json","targetId":"risk:ai-insufficient-human-oversight","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f11caf1f1bb12d16344326dccd7d4afb8595b36f64912f7c5fe131c6fb44116e","properties":{},"sourceDetailPath":"/data/v1/records/wf-c66-26a4ed19.json","sourceId":"wf:C66","targetDetailPath":"/data/v1/records/uc-uc-ai-19-535f3660.json","targetId":"uc:UC-AI-19","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f1b4a8472bf97ad9143ae40e4686cb83c55566975085fcda5dc8864209f8d27a","properties":{},"sourceDetailPath":"/data/v1/records/wf-c67-2d6bb2c2.json","sourceId":"wf:C67","targetDetailPath":"/data/v1/records/uc-uc-ai-19-535f3660.json","targetId":"uc:UC-AI-19","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fa29facda9059af8c7dae296732b036c55c71034cfce52f7069f4a40bfee6328","properties":{"control_id":"NIST-TEVV-06","coverage":"guidance","delta":null,"framework":"nist-ai-tevv-athlon","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Agent / tool abuse testing","source_version":"NIST AI 200-2 ipd (Initial Public Draft), August 2026"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-19-535f3660.json","sourceId":"uc:UC-AI-19","targetDetailPath":"/data/v1/records/ctrl-nist-ai-tevv-athlon-nist-tevv-06-6a69659d.json","targetId":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-06","type":"informed_by"}],"schemaVersion":1}
