AI Tool and Action Control Template
This template is used to define, approve, test, monitor, and evidence what tools, APIs, workflows, systems, and actions an AI capability can access or execute.
AI that can act creates a different risk profile from AI that only generates text.
The purpose of this template is to ensure AI tool use and action capability are explicitly inventoried, permissioned, classified, approval-gated, logged, monitored, reversible where possible, and containable.
1. Tool and Action Control Information
AI Use Case Name
[Enter AI use case name]
Tool/Action Control ID
[Enter control ID]
Date
[Enter date]
Prepared By
Name:
Function:
Email:
Business Owner
Name:
Function:
Email:
Technical Owner
Name:
Function:
Email:
Tool / Platform Owner
Name:
Function:
Email:
Not applicable reason, if any:
Related AI Inventory Record
Related Risk Assessment
2. AI Use Case Summary
Short Description
[Describe the AI use case]
AI Pattern
Select all that apply:
[ ] Copilot with tool access
[ ] Internal LLM application with tools
[ ] RAG system with tools
[ ] AI-enabled SaaS workflow
[ ] Embedded vendor AI action
[ ] Agent
[ ] AI-enabled workflow automation
[ ] Customer-facing AI with actions
[ ] Developer AI tool
[ ] Security operations AI
[ ] Decision-supporting AI
[ ] Action-capable AI
[ ] Other
Assigned Risk Tier
Select one:
[ ] Tier 1: Low-risk productivity or public-data use
[ ] Tier 2: Internal productivity with enterprise data
[ ] Tier 3: Decision-supporting AI
[ ] Tier 4: Action-capable AI
[ ] Tier 5: High-impact autonomous or regulated AI
3. Tool and Action Capability Summary
Can AI Use Tools, APIs, or Workflows?
[ ] No
[ ] Yes
[ ] Unknown
Capability Type
Select all that apply:
[ ] Read-only retrieval
[ ] Search
[ ] Draft-only action
[ ] API call
[ ] Workflow trigger
[ ] Ticket creation
[ ] Record creation
[ ] Record modification
[ ] Communication sending
[ ] Access request
[ ] Access approval
[ ] Financial transaction
[ ] Security action
[ ] Production system change
[ ] Administrative action
[ ] Code execution
[ ] Other
Tool and Action Summary
[Describe what the AI can do through tools, APIs, workflows, or integrations]
4. Tool Inventory
Tool Type
Select all that apply:
[ ] Read-only tool
[ ] Draft-only tool
[ ] Workflow tool
[ ] Write-capable tool
[ ] Communication tool
[ ] Transaction tool
[ ] Administrative tool
[ ] Security tool
[ ] Developer tool
[ ] External tool
[ ] Other
Tool Inventory Notes
[Describe tool ownership, scope, connected systems, and approval status]
5. Tool Permissioning
Permission Model
Select all that apply:
[ ] User permission inheritance
[ ] Delegated user authority
[ ] Service account permissions
[ ] Application identity permissions
[ ] Agent identity permissions
[ ] Vendor-managed permissions
[ ] Role-based permissions
[ ] Attribute-based permissions
[ ] Policy-based permissions
[ ] Other
Tool Permission Scope
Least Privilege Review Completed?
[ ] No
[ ] Yes
[ ] Partial
[ ] Unknown
Permission Notes
[Describe how tool access is limited to the approved use case]
6. Action Classification
Action Risk Classification
High-Risk Action Types
Select all that apply:
[ ] Customer-impacting action
[ ] Employee-impacting action
[ ] Financial action
[ ] Legal or compliance action
[ ] Security action
[ ] Production change
[ ] Access grant or revocation
[ ] Record modification
[ ] External communication
[ ] Regulated workflow action
[ ] Irreversible or hard-to-reverse action
[ ] Administrative action
[ ] Other
Action Classification Notes
[Describe action risk, reversibility, business impact, and classification rationale]
7. Action Boundaries
Boundaries Applied
Select all that apply:
[ ] Tool boundary
[ ] Data boundary
[ ] System boundary
[ ] Environment boundary
[ ] User boundary
[ ] Role boundary
[ ] Workflow boundary
[ ] Action boundary
[ ] Time boundary
[ ] Rate boundary
[ ] Amount boundary
[ ] Geography boundary
[ ] Customer segment boundary
[ ] Other
Boundary Table
Boundary Violation Response
[Describe what happens if AI attempts to exceed approved boundaries]
8. Approval Gates
Approval Required Before Action?
[ ] No
[ ] Yes
[ ] Conditional
[ ] Unknown
Approval Gate Summary
Approval Gate Type
Select all that apply:
[ ] User approval
[ ] Business owner approval
[ ] Technical owner approval
[ ] System policy approval
[ ] Workflow approval
[ ] Dual approval
[ ] Risk-based approval
[ ] Threshold-based approval
[ ] Exception approval
[ ] Security approval
[ ] Other
Approval Bypass Prevention
[Describe controls that prevent AI from executing high-risk actions without approval]
Approval Notes
[Describe approval flow, reviewer context, evidence, and escalation]
9. Autonomous Execution Limits
Autonomy Level
Select one:
[ ] Level 0: AI generates text only. No tool use.
[ ] Level 1: AI can suggest actions but not execute.
[ ] Level 2: AI can prepare actions as drafts. Human executes.
[ ] Level 3: AI can request actions but approval is required.
[ ] Level 4: AI can execute bounded low-risk actions.
[ ] Level 5: AI can execute high-impact actions only under strict controls.
Autonomous Execution Allowed?
[ ] No
[ ] Yes, low-risk only
[ ] Yes, with approval gates
[ ] Yes, with strict controls
[ ] Unknown
Autonomy Limits
[Describe limits on autonomous execution, planning, tool chaining, retries, escalation, and session duration]
10. Blast-Radius Limits
Blast-Radius Limits Applied
Maximum Potential Impact
[Describe maximum potential harm if AI fails, is misused, or is abused]
Blast-Radius Notes
[Describe how impact is constrained]
11. Tool Call and Action Logging
Tool Call Logging Required?
[ ] No
[ ] Yes
[ ] Unknown
Action Logging Required?
[ ] No
[ ] Yes
[ ] Unknown
Required Log Fields
Select all that apply:
[ ] AI system identity
[ ] Agent identity
[ ] Initiating user
[ ] Delegated authority
[ ] Session ID
[ ] Workflow ID
[ ] Tool called
[ ] Action requested
[ ] Parameters supplied
[ ] Data accessed
[ ] Approval required
[ ] Approval result
[ ] Action executed
[ ] Execution result
[ ] Error or exception
[ ] Timestamp
[ ] Downstream system affected
[ ] Rollback status
[ ] Policy decision
[ ] Other
Log Location
[Describe where tool call and action logs are stored]
Log Retention
[Describe retention period]
Log Access Restrictions
[Describe who can access tool/action logs]
12. Monitoring for Abnormal Tool Use
Monitoring Required?
[ ] No
[ ] Yes
[ ] Unknown
Monitoring Signals
Select all that apply:
[ ] Unusual tool call volume
[ ] Unusual action timing
[ ] Repeated failures
[ ] Excessive retries
[ ] Unauthorized tool call attempt
[ ] Approval bypass attempt
[ ] Blocked action attempt
[ ] Excessive data access
[ ] High transaction value
[ ] Action outside normal workflow
[ ] Tool use after policy violation
[ ] Prompt injection indicator
[ ] Unusual user-agent pairing
[ ] Other
Monitoring Response
Select all that apply:
[ ] Alert
[ ] Block
[ ] Require approval
[ ] Suspend tool access
[ ] Suspend agent
[ ] Revoke credentials
[ ] Open incident
[ ] Preserve evidence
[ ] Trigger review
[ ] Update controls
[ ] Other
Monitoring Notes
[Describe monitoring owner, alert routing, thresholds, and escalation]
13. Kill Switch and Revocation
Kill Switch Required?
[ ] No
[ ] Yes
[ ] Unknown
Kill Switch Levels
Select all that apply:
[ ] AI capability
[ ] Agent
[ ] Tool
[ ] API
[ ] Workflow
[ ] Identity
[ ] Vendor feature
[ ] User group
[ ] Action class
[ ] Data source
[ ] Environment
[ ] Other
Kill Switch Owner
Name:
Function:
Email:
Activation Conditions
[Describe when the kill switch should be activated]
Activation Process
[Describe how the kill switch is activated]
Expected Time to Disable
[Enter expected time]
Restart Criteria
[Describe approval, testing, and evidence required before restart]
Kill Switch Test
Last tested:
Result:
Evidence:
Next test:
14. Rollback and Compensation
Rollback Available?
[ ] No
[ ] Yes
[ ] Partial
[ ] Unknown
Rollback / Recovery Table
Compensation Required If Rollback Is Not Possible?
[ ] No
[ ] Yes
[ ] Unknown
Compensation Method
[Describe compensation, correction, notification, manual remediation, or record amendment]
Recovery Notes
[Describe rollback limitations, dependencies, approvals, and residual risk]
15. Incident Scenarios
Relevant Tool/Action Incident Scenarios
Select all that apply:
[ ] AI calls unauthorized tool
[ ] AI calls approved tool for unauthorized purpose
[ ] AI exceeds action boundary
[ ] AI bypasses approval gate
[ ] AI modifies incorrect record
[ ] AI sends unauthorized communication
[ ] AI triggers incorrect workflow
[ ] AI grants or revokes access incorrectly
[ ] AI executes financial action incorrectly
[ ] AI performs security action incorrectly
[ ] AI causes production impact
[ ] AI action cannot be rolled back
[ ] Tool logs are missing
[ ] Kill switch fails
[ ] Other
Incident Response Path
[Describe escalation, containment, evidence preservation, investigation, recovery, and communication path]
16. Testing and Assurance
Required Tests
Select all that apply:
[ ] Tool inventory test
[ ] Tool permission test
[ ] Unauthorized tool call test
[ ] Action boundary test
[ ] Approval gate test
[ ] Approval bypass test
[ ] Autonomous execution limit test
[ ] Blast-radius limit test
[ ] Tool call logging test
[ ] Action logging test
[ ] Abnormal tool use alert test
[ ] Kill switch test
[ ] Rollback test
[ ] Incident tabletop
[ ] Regression test
Test Results
Open Findings
17. Exceptions
Exceptions Required?
[ ] No
[ ] Yes
[ ] Unknown
Exception Summary
18. Approval
Business Owner Approval
Name:
Decision:
Date:
Notes:
Technical Owner Approval
Name:
Decision:
Date:
Notes:
Tool Owner Approval
Name:
Decision:
Date:
Notes:
Security / Architecture Approval
Name or forum:
Decision:
Date:
Notes:
Risk / Governance Approval
Name or forum:
Decision:
Date:
Notes:
Final Tool/Action Control Decision
Select one:
[ ] Approved
[ ] Approved with conditions
[ ] Approved for pilot only
[ ] Requires remediation
[ ] Requires exception approval
[ ] Requires additional testing
[ ] Rejected
[ ] Deferred
Approval Conditions
[List conditions required before approval, production use, scaling, or restart]
19. Review Triggers
Review this tool and action control design if any of the following occur:
[ ] New tool added
[ ] Tool permission changes
[ ] API integration changes
[ ] Workflow changes
[ ] Action classification changes
[ ] Approval gate changes
[ ] Autonomy level changes
[ ] User population changes
[ ] Data classification changes
[ ] Vendor feature changes
[ ] Risk tier changes
[ ] Incident occurs
[ ] Assurance finding occurs
[ ] Kill switch test fails
[ ] Rollback test fails
Next Review Date
[Enter date]
20. Summary
Use case:
Risk tier:
Tools available:
Action capability:
Highest-risk actions:
Approval gates:
Autonomy level:
Boundaries:
Blast-radius limits:
Logging:
Monitoring:
Kill switch:
Rollback:
Required testing:
Exceptions:
Approval status:
Next review date: