Filled diagram assumptions
Illustrative worked example. Names, volumes, dates, and outcomes are fictional; replace them with approved evidence before use.
| Component | Example responsibility | Failure behavior |
|---|---|---|
| Policy check | Scopes requested action | Returns denial |
| Planner | Proposes a bounded tool action | Stops when no permitted action exists |
| Approval gate | Shows target and action to owner | No execution without approval |
| Tool executor | Records result and source links | Creates failure record |
Sources: NIST AI Risk Management Framework · Supabase: securing data
Separate planning from execution
Show the user request, policy and identity check, planner, tool registry, approval gate, tool execution, durable state, and audit record as distinct units. A tool call should carry the scoped identity and an explicit permitted action; it should not inherit broad access simply because a user started a chat.
NIST’s AI RMF is a useful primary reference for risk governance. Apply it by making ownership, monitoring, and response paths visible rather than by adding an unsupported compliance label to the diagram.
Sources: NIST AI Risk Management Framework
Illustrative reference architecture
Illustrative worked example. Names, volumes, dates, and outcomes are fictional; replace them with approved evidence before use.
A procurement analyst asks the agent to assemble a comparison packet. The agent may search approved product sources and prepare a draft. Before it writes to a customer workspace or sends anything, an approval gate checks the user’s authority and the target scope. The tool executor records the input, source references, operation result, and any failure. A failed authorization returns a reviewable denial; it does not retry under a broader credential.
Sources: NIST AI Risk Management Framework · Supabase: securing data
Operating-responsibility table
| Component | Owner | Required control |
|---|---|---|
| Identity and policy | Application security | Scoped authorization and review |
| Agent planner | Product / engineering | Bounded instructions and tool selection |
| Tool executor | Engineering | Idempotency, error handling, audit record |
| Human approval | Named business owner | Visible target and action |
| Logs and retention | Security / privacy | Access, retention, incident path |
Sources: NIST AI Risk Management Framework · Supabase: securing data
Sources and dates
- NIST AI Risk Management Framework ↗
Primary framework reference for governance and risk discussions.
Reviewed 2026-09-08 - Supabase: securing data ↗
Official guidance on RLS and server-side access patterns.
Reviewed 2026-09-08
Found an error or a changed source? Send a correction.
Apply this to your company
Prepare materials for your next buyer conversation.
Accountmade helps technical B2B teams prepare demo decks, technical blueprints, business cases and security materials.
Explore Accountmade →