Skip to content
Home / Browse Q / QP-028
QP-028 • PF-04 Assessment

Check What an AI Agent Is Allowed to Do

Official Q product: Agent Runtime Authority and Failure Review - Self-Assessment Pack

This is an AI-authority review that helps you check what an AI helper is allowed to do, which tools or data it may use, and what should happen if it goes outside those rules.

Good for: AI vendors, platform teams, developers, security teams, and organizations using AI helpers that can take actions
Level 1 · Discover · Free

What is this, and why might you need it?

Start here. No purchase is required to understand the product.

What it is

This is an AI-authority review that helps you check what an AI helper is allowed to do, which tools or data it may use, and what should happen if it goes outside those rules.

What problem it helps with

Make sure an AI helper’s permissions are clear, limited, reviewable, and reversible before it is allowed to take meaningful actions.

Who it is for

AI vendors, platform teams, developers, security teams, and organizations using AI helpers that can take actions

Important limits

No production-security claim
Level 2 · Learn & Evaluate · Free

Study it before you buy it.

This is the pre-purchase learning and decision layer. It stays public even when the complete package is not yet ready to order.

Two-minute study

QP-028 — Agent Runtime Authority and Failure Review - Self-Assessment Pack
TWO-MINUTE RESEARCH PAPER · 1.0.0-r1 · 2026-09-25
STATUS: CANDIDATE RESEARCH — HUMAN/INDEPENDENT REVIEW REQUIRED

WHAT IT IS
This is an AI-authority review that helps you check what an AI helper is allowed to do, which tools or data it may use, and what should happen if it goes outside those rules.

PROBLEM
Make sure an AI helper’s permissions are clear, limited, reviewable, and reversible before it is allowed to take meaningful actions.

WHO IT IS FOR
AI vendors, platform teams, developers, security teams, and organizations using AI helpers that can take actions

WHY IT MATTERS
AI-enabled work can fail through weak evidence, stale information, unclear authority, privacy/security gaps, overconfident outputs, or automation that becomes practically irreversible. NIST's AI RMF provides a lifecycle risk-management frame; Q10 applies that direction by requiring explicit scope, evidence, human authority, limitations, review dates, stop conditions, and rollback.

HOW IT WORKS
Name a human owner; define scope; record evidence, unknowns and contradictions; define permissions and prohibited actions; run baseline and adversarial tests; patch and retest; record residual risk; create a dated release receipt; set a review/TTL date.

VALIDATION STATE
Real-runtime test and remediation readback
Generated research does not upgrade that evidence.

RISKS / FAILURE MODES
Scope creep; evidence drift; stale sources; authority escalation; false-clear from passing tests; privacy leakage; insecure dependencies; common-mode failure; reviewer fatigue; inaccessible interfaces; rollback failure; unsupported claims repeated as fact.

HUMAN CONTROL
A named human retains consequential approval, override, stop, release, and rollback authority.

KNOWN LIMITS
No production-security claim

REFERENCE BASIS
NIST AI Risk Management Framework 1.0; NIST Generative AI Profile; NIST Privacy Framework; NIST Cybersecurity Framework 2.0; OWASP Top 10 for LLM and GenAI; UNICEF Guidance on AI and Children v3.

BOUNDARY
Research/education material only. Not legal, medical, financial, engineering, safety-certification, or regulatory advice.
Open buyer / research paper

How it works

A separate operating explanation has not yet been recorded for this product. Review the buyer/research paper and technical details below for the currently documented implementation information.

AI boundaries & human responsibility

AI-specific allowed/not-allowed actions have not yet been separately recorded for this listing.

Risks, limits & failure modes

No production-security claim

Failure modes: no separate failure-mode record has been published for this listing yet.

Dependencies, compatibility & deployment

Dependencies: not separately recorded.

Evidence, testing & provenance

Real-runtime test and remediation readback

Provenance:
Factory source class: CANONICAL_82
Q spine/source basis: Agent Fabric; EH; TSLP; Ledger
Factory source: shopify:agent-runtime-authority-and-failure-review

Independent validation: No independent-validation status has been recorded; no independent validation is claimed by this listing.

Resources, privacy & security

Separate resource/energy requirements are not yet recorded on this listing.

Privacy and security obligations depend on the product and deployment. Where they have not yet been versioned in the legal/disclosure manifest, they remain an open pre-sale requirement rather than an implied promise.

What the complete package is expected to include

Architecture review and failure-mode packet

Price, license, support & updates

Price / pricing method: Request diagnostic • estimate after scope

License: Not yet recorded as a versioned license model.

Legal, rights & disclosures

A plain-language legal summary has not yet been versioned for this product.

Legal manifest status: LEGAL_SNAPSHOT_NOT_YET_VERSIONED

Level 3 · Complete Q Package

The order must deliver the complete promised package.

Level 3 is fulfillment, not more marketing. An email, request form, quote request, or buyer paper is not the purchased package.

What this version promises

Architecture review and failure-mode packet

Recorded package filename: QP-028_agent-runtime-authority-and-failure-review_v1.0.0.zip

Product version: 1.0.0

Order readiness

NOT READY TO ORDER YET

This listing stays open for Discover and Learn & Evaluate, but Q will not treat Level 3 as sale-ready until the complete-package proof is finished.

Package contents + version
Recorded
Fulfillment manifest
PACKAGE_LOCATED__CONTENTS_VERIFICATION_REQUIRED · manifest file missing
Legal/disclosure manifest
LEGAL_SNAPSHOT_NOT_YET_VERSIONED · legal snapshot file missing
Delivery path
PROVIDER_NOT_BOUND
Checkout release
HELD_UNTIL_PRODUCT_SPECIFIC_GATE_CLEARS
Release gate
Not cleared

Planning or configuring is not an order and does not count as fulfillment.

THE Q PATH

Discover → Learn & Evaluate → Complete Package.

Stop after learning, save it to My Q, combine it with other Q products, or order the complete implementation only when its delivery gate is actually ready.