What scopes should limit an AI agent's budget and actions?
Last reviewed 5 Sept 2026 · Review due 5 Mar 2027
Short answer
Limit agents with explicit scopes: allowed actions, resource selectors, spending or rate budgets, time expiry and revocation hooks. Require human approval for sensitive classes of action. Treat Ciright AI-authorization properties as related investigation seeds until verified, and never grant open-ended production authority by default.
Evidence
Standards education — authentication vs authorization
standards education · effective 2026-09-05 · retrieved 2026-09-05
Public reference
