Terminal-state gate: every run can finish without improvising
Attach objective, allowed resources, non-goals, input eligibility, success evidence, and exact states for complete, no work, blocked, cancelled, uncertain outcome, failed, and reconciled. PASS means the orchestrator can determine terminal state from observable evidence. REVIEW means a low-risk manual completion check has an owner and timeout. STOP covers improve indefinitely, keep trying, no maximum attempt, model self-certification, or task expansion when evidence is absent. Test restart from every state. The run must not repeat completed work or interpret a missing answer as permission to continue. A model's narrative about progress is not the state store.
Evidence: National Institute of Standards and Technology; OpenAI
Budget gate: limits are atomic, multidimensional, and nonrenewable by the agent
List turn, tool-call, retry, time, token, compute, currency, record, file, byte, network, recipient, privileged-action, and concurrency limits. PASS means the system reserves and enforces them before work, warns before exhaustion, and stops safely when accounting fails. REVIEW covers a conservative manual counter for an internal read-only pilot. STOP covers advisory prompt limits, shared counters vulnerable to races, unlimited retries, absent spend visibility, or automatic extension generated by the same agent. Simulate threshold crossing and concurrent workers. One low-cost destructive call still requires an action control; budgets do not replace permissions.
Evidence: National Institute of Standards and Technology; OWASP Gen AI Security Project
Capability gate: identity and tools cannot exceed the task
Inventory agent principal, user delegation, credential expiry, functions, parameter ranges, object scopes, data, destinations, and third-party connectors. PASS means least functionality, least permission, argument validation, read-only defaults, and attributable actions. REVIEW covers one unused read tool disabled before external launch. STOP covers generic administrator credentials, arbitrary command execution, broad database writes, unrestricted email or web access, hidden plugins, or untrusted retrieved text gaining authority. OWASP's excessive-agency guidance and NIST NCCoE's emerging identity work support these questions. Remove capability rather than relying on the model to choose restraint.
Evidence: National Cybersecurity Center of Excellence; OWASP Gen AI Security Project
Approval gate: consequential proposals are immutable and expire
Classify external communications, publication, payments, purchases, deletion, deployment, privileged changes, and sensitive-data transfers. PASS means an authorized person sees action, exact target, content or diff, evidence, cost, risks, rollback, and expiry before execution, and approval binds to that version. REVIEW covers reversible low-risk writes under a small batch cap. STOP covers approval after action, vague blanket consent, silent parameter substitution, auto-approval on timeout, or a reviewer unable to cancel. Test reject, timeout, edited proposal, withdrawn permission, and duplicate approval events. A confirmation modal without server-side enforcement is not a gate.
Evidence: National Cybersecurity Center of Excellence; OpenAI
Stuck-and-stop gate: independent controls interrupt real workers
Verify repeated-action fingerprints, no-progress windows, cycle detection, error ceilings, abnormal spend or volume, policy violation, heartbeat, user stop, and administrator kill. PASS means stops block new calls, cancel queued actions, preserve a checkpoint, and create a reconciliation task for unknown effects even when the model or provider is unavailable. REVIEW covers a measured cancellation delay in a read-only sandbox. STOP covers a button that merely prompts the model, workers that ignore revoked state, recursive repair loops, or lost checkpoints. Simulate stop during a tool call, network partition, restart, and approval wait. Record detection and recovery time without claiming one universal threshold.
Evidence: National Institute of Standards and Technology; OWASP Gen AI Security Project
Recovery ruling: prove rollback and reconciliation before granting writes
The next action is to run the release record in a sandbox with synthetic effects and resolve every STOP finding. Rehearse duplicate webhook, lost response after successful write, partial batch, provider outage, expired credential, corrupted state, and human takeover. Every REVIEW item needs owner, due date, narrow authority, and reason it cannot cross the harm boundary. Limits remain: distributed races and novel attacks persist, logs can fail, provider tools change, and passing tests do not justify broader autonomy. Release read and draft capability first; expand one action class at a time with incident monitoring. Commercial platforms and affiliate links remain subject to independent evaluation, visible disclosure, and the same enforceable stop requirements.
Sources and further reading
These references informed this article. A source supports a claim; it does not imply endorsement of TenMultigure or any future product reference.
- Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence ProfileNational Institute of Standards and Technology · Accessed August 10, 2026
NIST's Generative AI Profile grounds gates for governance, human roles, testing, monitoring, incident response, third-party systems, and ongoing risk management.
- Software and AI Agent Identity and AuthorizationNational Cybersecurity Center of Excellence · Accessed August 10, 2026
NIST NCCoE's 2026 agent-identity project informs checks for distinct principals, delegated authority, authorization, auditing, attribution, and revocation.
- LLM06:2025 Excessive AgencyOWASP Gen AI Security Project · Accessed August 10, 2026
OWASP Excessive Agency supplies an independent security basis for limiting available functions, permissions, and autonomy before deployment.
- Agents SDKOpenAI · Accessed August 10, 2026
OpenAI Agents documentation provides current provider-specific concepts for agents, tools, orchestration, guardrails, state, traces, and workflow evaluation.
Reviewed by TenMultigure AI Editorial Safety Review. See an error or a source that has changed? Tell the editorial team.
Review method: AI-assisted desk research with editorial checks. Reviewed ; next scheduled review . Turned anti-runaway review into pass-review-stop gates for terminal states, budgets, tools, identities, approvals, stuck detection, cancellation, uncertain effects, and incidents.