Two advisors evaluate an AI-assisted decision workflow
All services
AI and agent security

AI & agent security

Scope the data, permissions and approvals involved in an AI or agent project. Define the risks to examine before deciding to put it into use.

Loupe Technologies proposes scoping the risks of an AI use case or an agent that operates in your tools. We start with the intended task, data and actions to define the questions to examine and controls to plan for. The scope of technical assessments and implementation is clarified for each project.

Questions to address before expanding adoption

Several people are experimenting with tools without shared rules. You want to understand the proposed uses and the information they require.

Your project involves preparing a message, changing a record or triggering an operation. You need to define permitted actions and the decisions that remain with a person.

You want to understand the provider’s role, the information involved and the terms of use before deciding on a trial.

Scope a use case, its data and its actions

We propose describing the intended system with your business and IT owners: purpose, users, accessible information, connected tools and expected outcome. Scoping distinguishes a suggestion for review from an action that changes a record or has an external effect.

The engagement can prepare a scenario analysis and verification plan. It specifies what should be tested, by whom and with which data. Technical testing, agent development and ongoing operation are separate scopes to agree explicitly.

Define governance for AI use

Teams need rules they can apply in everyday work: who can propose a use case, what information can be processed, who approves an exception and when a decision needs reviewing. We propose connecting these questions to responsibilities already present in your organization.

Scoping can produce a register of proposed uses and a decision process: clarify a use case, prepare a trial, meet conditions or defer a decision. Each decision retains its rationale and owner.

Deliverables that help you decide project conditions

Depending on the agreed scope, deliverables may include:

An AI scope brief

The task, users, data, vendors and intended actions, with the unknowns that prevent a conclusion.

A decision and responsibility matrix

Steps requiring approval, the people involved and stopping or recovery conditions to examine with your owners.

A prioritized verification plan

Scenarios to assess, expected results and evidence to retain before deciding to expand the project or put it into use.

Prepare a decision grounded in the intended operation

  1. Describe a specific use case

    Start with a task and intended outcome. Identify the business owner and the teams that will use or administer the system.

  2. Map the exchanges

    Clarify input data, connected tools, destinations and possible actions. List the questions to ask providers.

  3. Prioritize what needs checking

    Select the situations to examine with the owners. Identify the information needed to accept, correct or reject an option.

  4. Document the conditions for proceeding

    Present the scope, known limitations and responsibilities. Agree separately on additional assessments or implementation work.

Questions before you start

Why examine an agent’s permissions?

An agent using tools can act on resources beyond generating text. OWASP recommends permissions limited to its task and authorization for sensitive operations. Scoping connects these controls to the actions planned in your project.

Is human approval enough to make an agent safe?

It is one control among several. OWASP also recommends tool restrictions, verification and monitoring. You need to examine what the person approves and the action’s consequences, without inferring system security from the presence of an approval button alone.

Is an AI risk management framework a certification?

The NIST AI RMF is voluntary and addresses AI risk management. Referring to it does not certify a system or replace a review of requirements relevant to your project. Our proposal specifies the work and expected outputs.

Can you start with scoping without building the agent?

Yes, that is the proposed starting point. Needs, dependencies and unknowns can be examined before an implementation decision. A prototype, technical testing or recurring operation is a separate scope to confirm.

Sources and references

  1. AI Agent Security Cheat Sheet — OWASP
  2. AI Risk Management Framework — NIST

Which AI use case would you like to scope?

Describe the task, the tools being considered and the decisions the system could make. We can then clarify the questions to examine and the boundaries of a scoping engagement.