Image: assets.insightmediagroup.io · rights & removal
How to Build a Control Plane for AI Agents
Reporting by Towards Data ScienceRead the original at towardsdatascience.com
Executive Summary
The article details the need for a control plane to govern how Large Language Models (LLMs) execute actions, moving beyond simple capability to establish authorization and accountability in agentic systems. It argues that current agent stacks are often deficient because they focus on generating tool calls without enforcing whether those actions are actually allowed or authorized. The core distinction is between capability—the ability of the model to select a tool—and authority—the separately enforced policy that permits a specific, bounded action for an identified principal in context.
The proposed solution involves organizing agentic systems into three planes: the planning plane (what the model knows), the control plane (what decides if actions are allowed), and the execution/observation plane (what performs and proves the effect). The text outlines nine steps to build this control plane, emphasizing that these steps move beyond simple prompt engineering and mandate external policy enforcement. Key mechanisms include structuring tools with explicit contracts, separating authentication from authorization, making authorization a deterministic decision outside the LLM, classifying actions by consequence (T0 through T4), binding approvals to canonical action representations, defending against prompt injection through context partitioning, managing uncertainty via state machines for retries, and establishing comprehensive audit records.
The framework posits that the agent should act as an upstream proposer, while the policy engine and tool boundaries handle authorization. This separation ensures that consequential actions are vetted by a dedicated control plane before execution, which is crucial for mitigating risks like prompt injection, unintended effects, and cascading failures inherent in autonomous systems.
Facts Only
* A support agent may select a tool to cancel a subscription based on model output.
* Schema validation confirms the syntactic validity of tool inputs.
* Authentication verifies who presented a request.
* Tool definitions specify what the model can request.
* Capability is the ability to select a tool and produce arguments.
* Authority is the permission from a separately enforced policy for a bounded action for an identified principal in context.
* The system should treat capability as a proposal and require authority before producing an effect.
* Agentic systems are organized into three planes: planning, control, and execution/observation.
* Action contracts should expose business-level verbs with explicit boundaries (e.g., create\draft\invoice).
* Actions are classified into tiers based on consequence: T0 observe, T1 draft, T2 reversible internal effect, T3 high impact / sensitive, and T4 critical / systemic.
* Approval must be bound to a canonical representation of the action, including target, parameters, and identities.
* Untrusted content is explicitly classified as untrusted data and quarantined before privileged agent use.
Full Take
The narrative pivots on establishing governance by fundamentally separating the cognitive function of reasoning (planning) from the operational necessity of authorization (control). The core implication is that autonomy, when granted to an LLM, must be explicitly bounded by external, deterministic policy rather than being implicitly trusted. This mirrors established security architectures like Zero Trust, where trust is never ambient but must be dynamically decided per request.
The progression through the nine steps outlines a necessary shift from an open-ended interaction loop (plan $\rightarrow$ tool call $\rightarrow$ observation) to a structured system where consequences are managed via state machines and immutable audit trails. The risk identified is that sophisticated agentic systems, despite apparent capability, remain vulnerable to real-world harm from ambiguous intent or injection by translating valid tool calls into adverse effects.
The T0 through T4 classification system is a critical mechanism for operationalizing risk management. It shifts the focus from a monolithic view of the agent to granular accountability, recognizing that autonomy should scale based on potential impact. The most potent pattern here is shifting accountability: moving trust away from the model's confidence and placing it onto external policy engines, execution brokers, and verifiable ledger systems. This reframes agentic development not as an exercise in maximizing model output but as designing resilient interfaces between unbounded reasoning and constrained physical action, forcing a recognition that "helpful" does not equal "authorized."
Bridge Questions: If the policy decision is perfect, what are the inherent risks associated with human-in-the-loop review delays? How can organizational structures evolve to support dynamic, contextual authorization checks rather than static permissions? What mechanisms exist to ensure the audit ledger itself remains impervious to manipulation by an entity that controls both the execution and observation planes?
From the original · Towards Data Science
Giving an LLM permission to act, in 9 steps Most agent stacks have become eerily good at turning model output into an action. But they're much less disciplined about answering the question that actually matters: "Is this action actually allowed to happen?"Read the full story at towardsdatascience.com
Sentinel — Human
This text reads like an expert architect distilling complex security and system design principles into actionable, structured steps, strongly suggesting human authorship rooted in deep technical experience.
