# AI Agent Runtime Authorization & Control Tools: evaluation worksheet

Source: https://dutygraph.com/directory/ai-governance/categories/runtime-controls/
Editorial date: 2026-09-07

## Scope

- Organization / team:
- Task and expected output:
- Human owner:
- Product and version:
- Evaluation date / environment:
- Reviewer:

## Questions

### 1. Where is the decision enforced, and can another connector bypass it?

- Observation (demonstrated / described / unknown):
- Evidence reference:
- Limitation or follow-up:

### 2. Is approval tied to the exact resource, action, payload and policy version?

- Observation (demonstrated / described / unknown):
- Evidence reference:
- Limitation or follow-up:

### 3. Does a failed policy lookup deny, defer or allow the action?

- Observation (demonstrated / described / unknown):
- Evidence reference:
- Limitation or follow-up:

### 4. How do expiry, replay prevention and emergency revocation work for pending actions?

- Observation (demonstrated / described / unknown):
- Evidence reference:
- Limitation or follow-up:

## Evidence checklist

- [ ] An enforcement-path diagram
- [ ] Denied bypass and altered-payload attempts
- [ ] Decision logs identifying the policy and approval versions

## Boundary to check

Runtime controls evaluate actions in their coverage. They do not establish whether the company's policy is correct, resolve an unclear business owner, or guarantee that an allowed action produces a good outcome.

## Decision

- Fit for the scoped task:
- Unresolved gaps:
- Next action, owner and date:

This is a planning worksheet, not an endorsement, access approval or compliance certification. Keep confidential evaluation notes in your organization's approved storage.
