OPEN-SOURCE / MODEL-NEUTRAL / PRE-ACTION

Before an AI system acts,
name the boundary.

Action Boundary Brief is a small shared record for turning a proposed AI-enabled action into an inspectable question: what may it touch, what may it do, who owns the exception, what stops it, and what must a later reviewer be able to see?

BOUNDARY RELAY / 01NO ACTION BY DEFAULT
The Action Boundary Brief relayA proposed action moves through five gates: intent, resources, right, interruption, and record. Each gate requires an explicit fact before the next stage can be reviewed.01INTENT02RESOURCE03RIGHT04PAUSE05RECORDWHY?WHAT?MAY?WHEN STOP?WHAT REMAINS?
METHOD NOTE The relay does not score a workflow or turn a checklist into a permission. It makes the gaps someone responsible needs to resolve visible.

THE WORKING PROBLEM Capability is often mistaken for authority. A model can produce a recommendation, a draft, or an instruction; it does not follow that the surrounding system should act on it without a stated boundary.

Five facts before
the handoff.

The brief is intentionally smaller than a policy or risk program. It is a preparation artifact: clear enough to expose what is missing, compact enough to travel between an operator, builder, reviewer, and accountable decision-maker.

  1. 01

    Intended outcome

    State the operational result, not the model feature. This keeps the proposed work tied to a real purpose.

  2. 02

    Resource envelope

    Name the data, tools, people, time, money, communications, and systems the work could affect. Put an owner and a limit beside each material resource.

  3. 03

    Decision right

    Separate observing, summarizing, recommending, drafting without sending, and executing within a named limit. List prohibited actions explicitly.

  4. 04

    Interruption

    Name the human who resolves exceptions, the condition that pauses the work, and the feasible stop or containment path.

  5. 05

    Review record

    Keep enough context for another person to reconstruct the source, candidate action, decision, result, and unresolved question.

The brief surfaces a
different question at each boundary.

Select a fictional case. The notes below are prewritten examples, not a decision engine, score, or real-world authorization.

CASE / DRAFT-01REQUESTED RIGHT / DRAFT ONLY

PROPOSED ACTION

Prepare—but do not send—a supplier update.

Resource envelope
Sanitized delivery status and an approved contact list. No contract files, price history, or private notes.
Boundary question
Is the workflow drafting text only, or has someone implicitly granted it an external communication right?
Pause trigger
The draft includes an unverified date, a commercial statement, a new recipient, or a request to commit.
Human next step
A named owner checks the draft, recipient, facts, and authorization before any person sends it.

A complete brief makes the boundary inspectable. It does not make the message correct or grant the right to send it.

Small enough for
the real handoff.

Use an Action Boundary Brief when an AI-enabled workflow could cross a meaningful threshold: non-public data, an external recipient, a live tool, another person’s schedule, a financial commitment, or an operational system.

Do not use it to mask a decision that needs specialized review. It cannot classify legal risk, assess a system’s safety, secure a live integration, or approve a production release.

Read the skill instructions

Useful because it
stays bounded.

01

NIST AI RMF

Frames AI risk work as voluntary and context-sensitive across Govern, Map, Measure, and Manage.

Read source ↗
02

NIST AI 600-1

Names governance, provenance, pre-deployment testing, and incident disclosure as primary Generative AI considerations.

Read source ↗
03

EU AI Act, Article 14

Describes proportionate human oversight, including monitoring, interpretation, override, intervention, and a halt path for high-risk systems.

Read source ↗
04

OWASP GenAI

Identifies excessive agency and overreliance as important application risks and points to ongoing open source security work.

Read source ↗

START WITH A RECORD, NOT A CLAIM

Make the limit
part of the work.

Download the template, use sanitized facts, name the person who owns the exception, and treat a passing format check as exactly that: evidence that the record is complete enough to review.

Use the template View source on GitHub