08 / BOUNDED ACTIONS

Agentic AI dapps.Define the boundaries.

A suggestion and an action are different capabilities. Give every tool a narrow purpose, an explicit permission boundary, and an observable result.

Inventory capabilities before adding autonomy

List everything the agent can read and change. Drafting content, creating a review item, publishing a page, changing deployment configuration, and initiating a transaction are separate operations. Define the resources and scope for each. A broad “manage project” capability can hide important differences from both reviewers and operators.

Separate proposal from authorization

A plan describes work; a proposal describes a concrete change; an approval authorizes that specific change. Show reviewers the affected resources, exact difference, supporting sources, and intended result. A materially revised proposal should not silently inherit an approval for the previous version.

Enforce at the tool boundary

Use controls outside the agent’s own reasoning to validate identifiers, allowed operations, and authorization. Keep the tool response factual about what changed and what remains unresolved. Where repeated requests are possible, design the action service to recognize previous work rather than relying only on conversational memory.

Build a stop and recovery procedure

Give an operator a clear way to suspend work, inspect pending actions, and revoke access. Decide what happens when a source is inconsistent or a tool returns an ambiguous result. Test with expired approvals and unexpected destinations in a non-production setting. Do not let an error become a reason to seek a more permissive route.

OWASP’s agent security guidance discusses tool access, least privilege, validation, and human oversight.

Read the agent security guidance

Questions to settle early

Should a documentation agent have a signing key?

A documentation task normally has no need for transaction authority. Introduce a separate, reviewed architecture only when a clearly defined task genuinely requires it.

Is a stronger prompt enough to enforce permissions?

Do not rely on a prompt as the sole authorization control. Validate and enforce the allowed operation in the surrounding tool or service.