Terminal-state gate: every run can finish without improvising

Attach objective, allowed resources, non-goals, input eligibility, success evidence, and exact states for complete, no work, blocked, cancelled, uncertain outcome, failed, and reconciled. PASS means the orchestrator can determine terminal state from observable evidence. REVIEW means a low-risk manual completion check has an owner and timeout. STOP covers improve indefinitely, keep trying, no maximum attempt, model self-certification, or task expansion when evidence is absent. Test restart from every state. The run must not repeat completed work or interpret a missing answer as permission to continue. A model's narrative about progress is not the state store.

Evidence: National Institute of Standards and Technology; OpenAI

Budget gate: limits are atomic, multidimensional, and nonrenewable by the agent

List turn, tool-call, retry, time, token, compute, currency, record, file, byte, network, recipient, privileged-action, and concurrency limits. PASS means the system reserves and enforces them before work, warns before exhaustion, and stops safely when accounting fails. REVIEW covers a conservative manual counter for an internal read-only pilot. STOP covers advisory prompt limits, shared counters vulnerable to races, unlimited retries, absent spend visibility, or automatic extension generated by the same agent. Simulate threshold crossing and concurrent workers. One low-cost destructive call still requires an action control; budgets do not replace permissions.

Evidence: National Institute of Standards and Technology; OWASP Gen AI Security Project

Capability gate: identity and tools cannot exceed the task

Inventory agent principal, user delegation, credential expiry, functions, parameter ranges, object scopes, data, destinations, and third-party connectors. PASS means least functionality, least permission, argument validation, read-only defaults, and attributable actions. REVIEW covers one unused read tool disabled before external launch. STOP covers generic administrator credentials, arbitrary command execution, broad database writes, unrestricted email or web access, hidden plugins, or untrusted retrieved text gaining authority. OWASP's excessive-agency guidance and NIST NCCoE's emerging identity work support these questions. Remove capability rather than relying on the model to choose restraint.

Evidence: National Cybersecurity Center of Excellence; OWASP Gen AI Security Project

Approval gate: consequential proposals are immutable and expire

Classify external communications, publication, payments, purchases, deletion, deployment, privileged changes, and sensitive-data transfers. PASS means an authorized person sees action, exact target, content or diff, evidence, cost, risks, rollback, and expiry before execution, and approval binds to that version. REVIEW covers reversible low-risk writes under a small batch cap. STOP covers approval after action, vague blanket consent, silent parameter substitution, auto-approval on timeout, or a reviewer unable to cancel. Test reject, timeout, edited proposal, withdrawn permission, and duplicate approval events. A confirmation modal without server-side enforcement is not a gate.

Evidence: National Cybersecurity Center of Excellence; OpenAI

Stuck-and-stop gate: independent controls interrupt real workers

Verify repeated-action fingerprints, no-progress windows, cycle detection, error ceilings, abnormal spend or volume, policy violation, heartbeat, user stop, and administrator kill. PASS means stops block new calls, cancel queued actions, preserve a checkpoint, and create a reconciliation task for unknown effects even when the model or provider is unavailable. REVIEW covers a measured cancellation delay in a read-only sandbox. STOP covers a button that merely prompts the model, workers that ignore revoked state, recursive repair loops, or lost checkpoints. Simulate stop during a tool call, network partition, restart, and approval wait. Record detection and recovery time without claiming one universal threshold.

Evidence: National Institute of Standards and Technology; OWASP Gen AI Security Project

Recovery ruling: prove rollback and reconciliation before granting writes

The next action is to run the release record in a sandbox with synthetic effects and resolve every STOP finding. Rehearse duplicate webhook, lost response after successful write, partial batch, provider outage, expired credential, corrupted state, and human takeover. Every REVIEW item needs owner, due date, narrow authority, and reason it cannot cross the harm boundary. Limits remain: distributed races and novel attacks persist, logs can fail, provider tools change, and passing tests do not justify broader autonomy. Release read and draft capability first; expand one action class at a time with incident monitoring. Commercial platforms and affiliate links remain subject to independent evaluation, visible disclosure, and the same enforceable stop requirements.

Sources and further reading

These references informed this article. A source supports a claim; it does not imply endorsement of TenMultigure or any future product reference.

  1. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence ProfileNational Institute of Standards and Technology · Accessed August 10, 2026

    NIST's Generative AI Profile grounds gates for governance, human roles, testing, monitoring, incident response, third-party systems, and ongoing risk management.

  2. Software and AI Agent Identity and AuthorizationNational Cybersecurity Center of Excellence · Accessed August 10, 2026

    NIST NCCoE's 2026 agent-identity project informs checks for distinct principals, delegated authority, authorization, auditing, attribution, and revocation.

  3. LLM06:2025 Excessive AgencyOWASP Gen AI Security Project · Accessed August 10, 2026

    OWASP Excessive Agency supplies an independent security basis for limiting available functions, permissions, and autonomy before deployment.

  4. Agents SDKOpenAI · Accessed August 10, 2026

    OpenAI Agents documentation provides current provider-specific concepts for agents, tools, orchestration, guardrails, state, traces, and workflow evaluation.

Reviewed for clarity and evidence

Reviewed by TenMultigure AI Editorial Safety Review. See an error or a source that has changed? Tell the editorial team.

Review method: AI-assisted desk research with editorial checks. Reviewed ; next scheduled review . Turned anti-runaway review into pass-review-stop gates for terminal states, budgets, tools, identities, approvals, stuck detection, cancellation, uncertain effects, and incidents.