AI Agent Control Template
This template is used to assess, design, approve, monitor, and contain AI agents.
An AI agent is an AI system that can pursue a goal, plan steps, use tools, call APIs, trigger workflows, retrieve data, or perform actions with some level of autonomy.
Agentic AI requires stronger control than passive AI because it can move from generating output to executing actions.
1. Agent Information
Agent Name
[Enter agent name]
Agent ID
[Enter agent ID]
Date
[Enter date]
Agent Status
Select one:
[ ] Proposed
[ ] Under review
[ ] Approved
[ ] Pilot
[ ] Production
[ ] Restricted
[ ] Suspended
[ ] Under remediation
[ ] Retired
[ ] Rejected
Related AI Use Case
Related AI Inventory Record
Business Owner
Name:
Function:
Email:
Technical Owner
Name:
Function:
Email:
Agent Owner
Name:
Function:
Email:
Incident Contact
Name:
Function:
Email:
Escalation path:
2. Agent Purpose
Business Purpose
[Describe why this agent is needed and what business outcome it supports]
Agent Goal
[Describe the goal the agent is designed to pursue]
Approved Use Cases
[List approved use cases for this agent]
Prohibited Use Cases
[List prohibited or restricted uses]
User Population
Select all that apply:
[ ] Employees
[ ] Contractors
[ ] Developers
[ ] Security team
[ ] Customer support team
[ ] HR team
[ ] Finance team
[ ] Legal or compliance team
[ ] Business operations team
[ ] Customers
[ ] Suppliers
[ ] Partners
[ ] Public users
[ ] Other
3. Agent Autonomy
Autonomy Level
Select one:
[ ] Level 0: AI generates text only
[ ] Level 1: AI suggests actions but cannot execute
[ ] Level 2: AI prepares drafts but human executes
[ ] Level 3: AI requests actions but approval is required
[ ] Level 4: AI executes bounded low-risk actions
[ ] Level 5: AI executes high-impact actions under strict controls
Autonomy Description
[Describe what the agent can do independently and where human involvement is required]
Human Review Model
Select one:
[ ] Human-in-the-loop
[ ] Human-on-the-loop
[ ] Human-over-the-loop
[ ] Exception-based review
[ ] Not yet defined
Autonomy Limits
[Describe limits on planning, tool use, action execution, workflow scope, session length, or decision authority]
4. Agent Identity and Authority
Agent Identity Model
Select all that apply:
[ ] Direct user identity
[ ] Delegated user authority
[ ] Service identity
[ ] Application identity
[ ] Agent identity
[ ] Vendor-managed identity
[ ] Hybrid identity
[ ] Unknown
Agent Identity Details
Agent identity:
Service account:
Application identity:
Vendor identity:
Other:
Delegated Authority
Access Scope
[Describe systems, repositories, APIs, workflows, tools, and data the agent can access]
Access Approval
Approver:
Date approved:
Approval reference:
Access Review Frequency
Select one:
[ ] Monthly
[ ] Quarterly
[ ] Semi-annually
[ ] Annually
[ ] At material change
[ ] Other
Revocation Path
[Describe how agent identity, delegated authority, tool access, API access, or service credentials can be revoked]
5. Data Boundary
Data Sources Accessible to Agent
Data Classes Accessible
Select all that apply:
[ ] Public
[ ] Internal
[ ] Confidential
[ ] Restricted
[ ] Regulated
[ ] Personal data
[ ] Customer data
[ ] Employee data
[ ] Financial data
[ ] Legal or privileged data
[ ] Security-sensitive data
[ ] Source code
[ ] Secrets or credentials
[ ] Production data
[ ] Other sensitive data
Retrieval Boundaries
[Describe what the agent can and cannot retrieve]
Data Restrictions
[Describe restricted data, prohibited data, masking, minimization, retention, or reuse restrictions]
Vendor Processing
[Describe whether agent inputs, context, outputs, logs, or tool calls are processed by a vendor]
6. Prompt and Input Control
Input Sources
Select all that apply:
[ ] User prompt
[ ] System prompt
[ ] Retrieved document
[ ] Email
[ ] Ticket
[ ] Chat message
[ ] Customer submission
[ ] API payload
[ ] Tool response
[ ] Web content
[ ] Code
[ ] Log data
[ ] Workflow state
[ ] Conversation history
[ ] Memory
[ ] Other
External or Untrusted Inputs
[Describe external or untrusted inputs processed by the agent]
Prompt Injection Risk
Select one:
[ ] Low
[ ] Moderate
[ ] High
[ ] Critical
[ ] Unknown
Prompt Injection Controls
[Describe controls to prevent untrusted content from overriding system instructions or causing unsafe tool use]
System Prompt Protection
[Describe system prompt ownership, versioning, access control, testing, and rollback]
Context Isolation
[Describe how context is isolated across users, sessions, tenants, repositories, trust levels, and data classifications]
7. Tool Inventory
Tools Available to Agent
Tool Permissioning
[Describe which tools are allowed, restricted, prohibited, or conditionally available]
Prohibited Tools
[List tools, APIs, workflows, or actions the agent must not use]
Tool Access Review
Review frequency:
Reviewer:
Last reviewed:
Next review:
8. Action Classification
Agent Actions
High-Risk Actions
Select all that apply:
[ ] Customer-impacting action
[ ] Employee-impacting action
[ ] Financial action
[ ] Legal or compliance action
[ ] Security action
[ ] Production change
[ ] Access grant or revocation
[ ] Record modification
[ ] External communication
[ ] Regulated workflow action
[ ] Irreversible or hard-to-reverse action
[ ] Other
Action Notes
[Describe action risks, reversibility, downstream impact, and approval expectations]
9. Approval Gates
Approval Required Before Execution?
[ ] No
[ ] Yes
[ ] Conditional
[ ] Unknown
Approval Gate Summary
Approval Conditions
[Describe thresholds, conditions, or exceptions that require approval]
Approval Bypass Prevention
[Describe controls that prevent the agent from bypassing approval]
10. Execution Boundaries
Boundaries Applied
Select all that apply:
[ ] Tool boundary
[ ] Data boundary
[ ] System boundary
[ ] Environment boundary
[ ] User boundary
[ ] Role boundary
[ ] Workflow boundary
[ ] Action boundary
[ ] Time boundary
[ ] Rate boundary
[ ] Amount boundary
[ ] Geography boundary
[ ] Customer segment boundary
[ ] Other
Boundary Details
[Describe exact execution boundaries]
Boundary Enforcement
[Describe how boundaries are technically or procedurally enforced]
Boundary Violation Response
[Describe what happens if the agent attempts to exceed boundaries]
11. Blast-Radius Limits
Limits Applied
Blast-Radius Notes
[Describe maximum potential impact if the agent fails or is misused]
12. Monitoring and Logging
Logs Required
Select all that apply:
[ ] Agent session logs
[ ] User prompt logs
[ ] Prompt metadata
[ ] Retrieved context logs
[ ] Tool call logs
[ ] Action logs
[ ] Approval logs
[ ] Policy decision logs
[ ] Boundary violation logs
[ ] Error logs
[ ] Output logs
[ ] Monitoring alerts
[ ] Incident records
Required Log Fields
Select all that apply:
[ ] User identity
[ ] Agent identity
[ ] Delegated authority
[ ] Session ID
[ ] Goal or request
[ ] Plan or reasoning summary
[ ] Tool selected
[ ] Tool input
[ ] Tool output
[ ] Action requested
[ ] Action executed
[ ] Approval status
[ ] Result
[ ] Exception
[ ] Timestamp
[ ] Policy decision
[ ] Error or failure
Log Location
[Describe where logs are stored]
Log Retention
[Describe retention period and access restrictions]
Monitoring Rules
[Describe monitoring rules for abnormal tool use, action volume, policy violations, failed approvals, prompt injection, or unusual behavior]
13. Kill Switch and Containment
Kill Switch Available?
[ ] No
[ ] Yes
[ ] Partial
[ ] Unknown
Kill Switch Level
Select all that apply:
[ ] Agent level
[ ] Tool level
[ ] API level
[ ] Workflow level
[ ] Identity level
[ ] Data source level
[ ] Vendor feature level
[ ] User group level
[ ] Action category level
[ ] Environment level
Kill Switch Owner
Name:
Function:
Email:
Activation Conditions
[Describe when the kill switch should be activated]
Activation Process
[Describe how the kill switch is activated]
Expected Time to Disable
[Enter expected time]
Restart Conditions
[Describe approval and testing required before restart]
Last Kill Switch Test
Date:
Result:
Evidence:
14. Rollback and Recovery
Rollback Available?
[ ] No
[ ] Yes
[ ] Partial
[ ] Unknown
Rollback / Recovery Summary
Compensation Required If Rollback Is Not Possible?
[ ] No
[ ] Yes
[ ] Unknown
Compensation Method
[Describe compensation, correction, customer notification, manual remediation, or record amendment]
Recovery Notes
[Describe recovery constraints, dependencies, and approval requirements]
15. Assurance and Testing
Required Agent Tests
Select all that apply:
[ ] Agent identity test
[ ] Tool permission test
[ ] Unauthorized tool call test
[ ] Prompt injection to action test
[ ] Approval bypass test
[ ] Action boundary test
[ ] Blast-radius limit test
[ ] Logging completeness test
[ ] Kill switch test
[ ] Rollback test
[ ] Incident tabletop
[ ] Regression test
Test Results Summary
Open Findings
16. Incident Scenarios
Relevant Agent Incident Scenarios
Select all that apply:
[ ] Agent performs unauthorized action
[ ] Agent calls unauthorized tool
[ ] Agent follows prompt injection
[ ] Agent leaks data through tool use
[ ] Agent modifies incorrect record
[ ] Agent sends unauthorized communication
[ ] Agent loops or retries excessively
[ ] Agent exceeds blast-radius limit
[ ] Agent bypasses approval
[ ] Agent causes customer impact
[ ] Agent causes production impact
[ ] Agent causes security impact
[ ] Agent cannot be stopped quickly
[ ] Agent action cannot be rolled back
Incident Response Path
[Describe escalation, containment, evidence preservation, investigation, recovery, and communication path]
17. Risk Assessment
Agent Risk Rating
Select one:
[ ] Low
[ ] Medium
[ ] High
[ ] Critical
Risk Drivers
Select all that apply:
[ ] Sensitive data access
[ ] Regulated data access
[ ] Tool/action capability
[ ] High autonomy
[ ] Customer impact
[ ] Employee impact
[ ] Financial impact
[ ] Security impact
[ ] Production impact
[ ] External communication
[ ] Vendor dependency
[ ] Weak logs
[ ] Weak rollback
[ ] Weak kill switch
[ ] Prompt injection exposure
[ ] Approval bypass risk
Risk Notes
[Describe agent risk and residual risk]
18. Approval Decision
Decision
Select one:
[ ] Approved
[ ] Approved with conditions
[ ] Approved for pilot only
[ ] Requires remediation
[ ] Requires additional testing
[ ] Requires exception approval
[ ] Rejected
[ ] Deferred
Conditions
[List required conditions before agent approval, production use, scaling, or restart]
Exceptions Required?
[ ] No
[ ] Yes
[ ] Unknown
Residual Risk Acceptance Required?
[ ] No
[ ] Yes
[ ] Unknown
19. Approval Record
Business Owner Approval
Name:
Decision:
Date:
Notes:
Technical Owner Approval
Name:
Decision:
Date:
Notes:
Security / Architecture Approval
Name or forum:
Decision:
Date:
Notes:
Risk / Governance Approval
Name or forum:
Decision:
Date:
Notes:
Incident Response Approval, If Required
Name or forum:
Decision:
Date:
Notes:
20. Summary
Agent:
Use case:
Owner:
Autonomy level:
Identity model:
Data accessed:
Tools available:
High-risk actions:
Approval gates:
Blast-radius limits:
Kill switch:
Rollback:
Logging:
Testing status:
Risk rating:
Approval status:
Next review date: