Lab 004 · The Agent Escalation Boundary

The Agent Escalation Boundary

Authorization tells an agent what it may do. Judgment determines when it should not continue alone.

An agent can be authorized to act and still need to pause. This Lab explores the point at which an agent should proceed independently, ask for clarification, escalate the decision, or stop completely.

This Lab is an educational policy prototype using fictional data. It does not make real security decisions and should not be used as a production authorization or incident-response system. Execution is never performed.

Previous Lab: Agent Access Control Browse all Labs

Two questions, not one

Authorization asks

May this agent perform this action?

Outcomes: ALLOW · CONFIRM · STEP_UP · DENY

Execution judgment asks

Should this agent continue alone under the conditions that exist now?

Outcomes: PROCEED · CLARIFY · ESCALATE · STOP

Scenario

A Cedar Quill Markets security operations agent detects signs that an employee account may be compromised. The agent has delegated authority to revoke sessions and temporarily suspend access, but the available evidence and business context may conflict.

Unusual login location, a newly observed device, sensitive-file access, an important customer meeting in progress, possible legitimate travel, production-workflow impact, attacker-continuation risk, and a defined incident-response escalation contact.

Presets

Select a preset to fill every control, then run judgment — or adjust the factors yourself.

Judgment factors

Situation factors
Context and authority

Decision

Adjust the situation above, or choose a preset, then run judgment. No real security action is performed.

Decision summary

Context and authority feed uncertainty and consequence evaluation. The agent then selects an execution posture and records why it proceeded or paused.

Flow from context and authority through uncertainty evaluation to proceed, clarify, escalate, or stop, then explain and record.

Teaching notes

Authorization answers whether an action is permitted. Execution judgment answers whether the agent should finish that action alone given evidence, impact, reversibility, time, and human availability. A trustworthy agent recognizes when continuing alone would be unsafe.

Every evaluation reports execution: not_performed. This Lab is an educational policy prototype using fictional data. It does not make real security decisions and should not be used as a production authorization or incident-response system.

The companion Edition 4 newsletter will be linked here after publication. View source on GitHub From My Desk Labs