Safety & Security · Software component
Action Policy Engine
Software componentSafety & SecuritySafety, Security & Governancearc:ActionPolicyEngine
A policy enforcement component that authorises or blocks agent actions and tool access against permission scopes and safety prerequisites such as approvals, backups, or tickets.
Responsibility. Authorises and limits agent actions.
Also known as: Permission controls, Safety policy, Policy guardrails, Permission boundaries, Pre-Action Safety Validator, MCP authorization, Action classifier, Layer 3 business logic and autonomous action controls, Permission guardrails, Tool-specific privilege boundary, Tool executor permission check, Policy Enforcer, Automated policy enforcement, Approval-blocking guardrail, Hard block, Policy engine, Policy enforcement layer, Policy enforcement middleware, Policy Decision Point (HOvL)
Relationships
is configured by structural
- Action Risk Tier Policy Ch9.1 Ch10.5 +1
- Action Sequence Policy Ch3.8
- Agent-Specific Policy Ch10.5
- Approval Authority Matrix Ch10.5
- Data Classification Policy Ch10.5
- Departmental Policy Ch10.5
- Compliance Policy Rule Set Ch10.4
- Organizational Baseline Policy Ch10.5
- Policy Enforcement Mode Configuration abstract Ch10.5
- Team Policy Ch10.5
- Violation Response Policy abstract Ch10.4
invokes dependency
reads dependency
writes dependency
emits telemetry to dynamic
escalates to dynamic
receives data from dynamic
routes to dynamic
sends data to dynamic
triggers dynamic
constrains control
- Agent Controller abstract Ch1.2 Ch10.5
controls access to control
guards control
is evaluated by assurance
Design guidance
- MUST restrict each agent's tool access to the scope of its intended responsibilities.
- SHOULD explain blocked actions and show the approval path to proceed.
- SHOULD prevent policy-violating actions so agents operate within guardrails.
- SHOULD restrict knowledge queries to documents the requesting user is authorized to access.
- MAY provide fine-grained access control over tools published through a tool protocol server.
- MUST prohibit unknown actions by default.
- SHOULD govern actions independently of content toxicity: a politely phrased destructive action is still unsafe.
- MUST verify explicit permission and tool-specific domain constraints (e.g., target path within approved directories) for high-risk tools even after gateway checks pass.
- SHOULD grade policy violations as BLOCK (reject the action), WARN (log a warning) or AUDIT (record for audit).
- MUST enforce inviolable policy constraints on approved actions independently of approval authority, so even senior approvers cannot authorize violations.
- MUST intercept every agent action as middleware between the agent's decision logic and the target tool or system, before execution.
- SHOULD enforce hard constraints on tool access and data flow outside the model, in the execution layer, so prompt manipulation cannot bypass them.
- SHOULD express policies as near-natural-language IF-THEN conditional logic readable by non-technical stakeholders yet precisely evaluable.
- SHOULD differentiate categorically prohibited actions (hard block) from actions that are permissible with authorization (escalation).
- SHOULD NOT be relied on alone; layer it with guardrails, human oversight, monitoring and incident response (defense in depth).
Quantitative guidance
As stated by the sources; verify before use.
- Pre-execution validation caught 94% of healthcare safety violations (Ch3.8).
- Example decision tree: internal transfers < $10,000 auto-execute; internal transfers > $10,000 execute with enhanced logging and fraud-team notification; external transfers of any amount require explicit human approval (Ch10.5).
Classification
- Patterns
- Least privilegePre-action prerequisite validationTool-level privilege boundaries (defense-in-depth Layer 2)Human-over-the-loop (HOvL)Policy-based constraint enforcementSeparation of policy design from policy executionGraduated risk responseDefense in depthHard block vs. escalation
- Quality attributes
- Security (ISO/IEC 25010 | NIST AI RMF: secure and resilient)Safety (ISO/IEC 25010 | NIST AI RMF: safe)Transparency and accountability (NIST AI RMF: accountable and transparent)
- Risks mitigated
- Privilege escalationOver-privileged agentAccidental destructive actionsTool name exploitationDestructive high-risk tool calls (file deletion, database modification, shell execution)Data exfiltration via tool callsPrompt-injection bypass of prompt-based controlsAgent exceeding authority limitsCatastrophic literal interpretation of vague instructions
- Frameworks & regulations
- GDPREU AI Act
Sources
- Ch1.1A: T. Nguyen, "Designing User Interfaces for Intuitive Human-Agent Interaction," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 1.1A. ISBN: 9798244538229.
- Ch1.2: T. Nguyen, "Core Agent Patterns," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 1.2. ISBN: 9798244538229.
- Ch2.6: T. Nguyen, "Tool Integration and Function Calling," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 2.6. ISBN: 9798244538229.
- Ch3.3: T. Nguyen, "Web Navigation and Interaction Benchmarks," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 3.3. ISBN: 9798244538229.
- Ch3.8: T. Nguyen, "Action Accuracy Metrics," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 3.8. ISBN: 9798244538229.
- Ch9.1: T. Nguyen, "Output Filtering and Content Moderation," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.1. ISBN: 9798244538229.
- Ch9.2: T. Nguyen, "Action Constraints and Permission Models," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.2. ISBN: 9798244538229.
- Ch10.4: T. Nguyen, "Human-in-the-Loop," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 10.4. ISBN: 9798244538229.
- Ch10.5: T. Nguyen, "Human-over-the-Loop," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 10.5. ISBN: 9798244538229.
- Ref3.07: NVIDIA, "NeMo-Agent-Toolkit," GitHub repository. Accessed: Sep. 27, 2026. [Online]. Available: https://github.com/NVIDIA/NeMo-Agent-Toolkit
- Ref3.10: "Powering the Next Generation of AI Agents," unpublished reference note (10-Powering-Next-Generation-AI-Agents.md), Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam supplementary materials, 2026. unpublished note
- Ref9.04: "Safety Guardrails Implementation for Agent Systems," unpublished reference note (04-Safety-Guardrails-Implementation.md), Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam supplementary materials, 2026. unpublished note
- Ref9.09: "Compliance Automation and Tools," unpublished reference note (09-Compliance-Automation-Tools.md), Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam supplementary materials, 2026. unpublished note