Safety & Security · Data artifact
Action Risk Tier Policy
Data artifactSafety & SecuritySafety, Security & Governancearc:ActionRiskTierPolicy
An externalized configuration classifying each agent action as autonomous, approval-required or prohibited, with unknown actions defaulting to prohibited.
Responsibility. Assigns every agent action a risk tier.
Also known as: Action policies, Action classification policy, Decision authority boundaries, Graduated autonomy tiers, Graduated response policy, Decision boundary map
Relationships
configures structural
is read by dependency
Design guidance
- MUST default unknown actions to PROHIBITED (fail secure).
- SHOULD be stored in a configuration file or database so security teams can modify policies without code changes.
- SHOULD allow runtime context (user, circumstances) to change an action's decision.
- SHOULD tier actions by risk and reversibility: routine reversible actions autonomous, irreversible or high-impact actions (freezing accounts, blocking transactions, contacting customers, deleting repositories, committing to protected branches) approval-required.
- SHOULD partition the operational space along multiple dimensions simultaneously (data classification, transaction value, reversibility) rather than a single approval threshold.
Classification
- Patterns
- Fail secureThree-tier action classificationRisk-based decision boundariesReversibility-based tiering
- Risks mitigated
- Accidental privilege escalation from unclassified new capabilities
Sources
- Ch9.1: T. Nguyen, "Output Filtering and Content Moderation," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.1. ISBN: 9798244538229.
- Ch10.2: T. Nguyen, "Proactive Agents," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 10.2. ISBN: 9798244538229.
- Ch10.4: T. Nguyen, "Human-in-the-Loop," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 10.4. ISBN: 9798244538229.
- Ch10.5: T. Nguyen, "Human-over-the-Loop," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 10.5. ISBN: 9798244538229.
- Ref9.04: "Safety Guardrails Implementation for Agent Systems," unpublished reference note (04-Safety-Guardrails-Implementation.md), Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam supplementary materials, 2026. unpublished note