AI Governance Institute
← Agentic AI
AGT · Agentic AIAGT-007Medium effortAgent-relevant

Agent Scope and Task Boundaries

Added May 2026

Set and enforce each agent’s permitted activity. Prevent actions beyond its intended purpose.

Objective

Prevent scope creep (agents drifting into tasks they were not meant to do) in autonomous agent workflows by setting explicit task boundaries and catching deviations as they happen.

Maturity Levels

1

Initial

Agent scope is informally described in natural language with no enforced boundaries.

2

Developing

Scope limitations exist in the system prompt but are not enforced through system permissions and can be overridden by the AI model's own reasoning.

3

Defined

Agent scope is enforced through a combination of system prompt constraints, permission restrictions, and checks on the agent's outputs.

4

Managed

Scope deviations are detected and alerted in live use; patterns are reviewed to identify systematic boundary weaknesses.

5

Optimizing

Scope enforcement is continuously tightened based on observed deviation patterns and new threat intelligence (information about emerging attacks).

Evidence Requirements

What an auditor or assessor would expect to see for this control.

  • —Scope definition document for each agent, with tracked version history, signed by AI Platform Lead and Chief Information Security Officer (CISO) at each release
  • —Permission configuration records confirming scope is enforced through access permissions, not solely via the system prompt (the agent's standing written instructions)
  • —Scope violation alert logs showing deviations detected, blocked, and responded to within the defined service level agreement (SLA) time
  • —Adversarial scope expansion test results: attempts to instruct agent beyond its defined boundaries, with pass/fail outcome
  • —Scope change records showing formal review whenever agent capabilities were modified or extended

Implementation Notes

Key steps

  • Build task boundaries into the system's settings, not just its instructions: if an agent should only read emails (not send), block sending through its access permissions.
  • Monitor the agent's outputs to catch actions that are technically permitted but fall outside the agent's defined task.
  • Run adversarial tests (deliberate misuse attempts) aimed at scope expansion: try to instruct the agent to act beyond its boundaries and verify that boundaries hold.
  • Review scope definitions when agent tasks evolve; scope creep often happens gradually through small additions to what the agent can do.

Example Implementation

Enterprise deploying an AI agent for Tier 1 customer support ticket triage and response

Scope Definition: Customer Support Triage Agent

Permitted actions:

  • Read open tickets assigned to support queue
  • Classify ticket by issue type and priority
  • Draft a response (stored as draft, not sent)
  • Add internal notes to a ticket
  • Escalate ticket to a named human agent

Explicitly prohibited actions (enforced at permission layer, not prompt):

  • Send any communication to a customer (all drafts require human approval)
  • Access tickets outside the designated support queue
  • Modify ticket ownership or SLA settings
  • Access billing, account management, or CRM systems
  • Invoke any tool not on the above permitted list

Scope deviation monitoring: Any tool call to a resource outside the permitted list is logged as a scope violation, blocked at the framework layer, and triggers an alert to the AI Platform team within 15 minutes

Scope review: Scope definition reviewed and re-signed by AI Platform Lead and CISO at each quarterly agent version release

Control Details

Control ID
AGT-007
Typical owner
AI Engineering / AI Governance Team
Implementation effort
Medium effort
Agent-relevant
Yes

Tags

scope controltask boundariesagent governancecontainment

Templates for this control

Get control updates weekly

New and updated controls, maturity guidance, and the regulatory changes behind them. Every Thursday.

Powered by Buttondown.