Black
Agent Containment

Ensure Human-in-the-Loop Controls

Pause high-risk agent actions for informed human review and one-click approval. Keep people accountable for consequential decisions without slowing routine automation.

Use Case

Autonomous agents can handle routine work independently, but consequential actions still require human judgment. PointGuard AI automatically pauses defined high-risk actions, notifies the appropriate approver with clear activity and risk context, and allows that person to approve or deny execution with one click.

Challenges

Human oversight often fails when notifications arrive too late or lack enough context for a confident decision:

  • Agents can execute consequential actions before review
  • Generic alerts omit identity, intent, and business impact
  • Approvers struggle to assess technical agent activity quickly
  • Slow, fragmented approval processes interrupt productive automation

Solution

PointGuard AI provides a comprehensive solution that inserts informed human authorization before defined high-risk agent actions execute:

1. Define approval requirements. Use Agent Mission Control and MCP Security Gateway to identify sensitive resources, operations, risk levels, and policy conditions that require human authorization.

2. Intercept and pause the action. Evaluate each proposed action before execution and automatically hold requests that meet approval criteria.

3. Notify the right approver. Send the designated user clear guidance on the agent, intended action, target resource, delegated authority, policy reason, risk, and potential impact.

4. Approve or deny with one click. Allow the action to proceed only after approval, block denied requests, and record the decision with its supporting context for audit and investigation.

Human-in-the-loop controls preserve accountable decision-making for consequential actions while allowing routine agent activity to continue efficiently.

Risks Addressed

Applicable framework risks and controls include:

OWASP Top 10 for LLMs
  • LLM03:2026 Excessive Agency
OWASP Top 10 for Agentic Applications
  • ASI02: Tool Misuse and Exploitation
  • ASI03: Identity and Privilege Abuse
  • ASI09: Human-Agent Trust Exploitation
  • ASI10: Rogue Agents
NIST AI Risk Management Framework
  • GOVERN 1.4: Transparent risk policies, procedures, and controls are established
  • GOVERN 2.1: Roles, responsibilities, and communication are documented and clear
  • MAP 1.1: Intended use, context, users, and lifecycle risks are documented
  • MEASURE 2.7: AI system security and resilience are evaluated and documented
  • MANAGE 4.1: Post-deployment monitoring and change management are implemented