The full lifecycle of an automated action
A readable action connects intent, context, policy, control, authorization, action, observation, reconciliation, and evidence.
Objectives
- Identify breaks between stages.
- Distinguish evidence of a decision from evidence of an outcome.
- Duration
- 11 min
- Level
- Intermediate
Prerequisites
- Automation, autonomous systems, and agents
Concepts
Concepts
Decision chain
Every stage has an input, rule, output, and limitation that should remain traceable.
Observation and reconciliation
Observation reports a state; reconciliation compares it with what was expected without filling in unknowns.
Bounded evidence
Evidence supports a precise claim for a given object and version without automatically validating everything else.
Human responsibility
Designated people or roles remain responsible for policy, final authority, oversight, stopping, and responding to consequences.
Visual guide
From intent to evidence
- Intent and context.
- Policy, control, and authorization.
- Action and observation.
- Reconciliation and bounded evidence.
Synthetic example
Synthetic example
An action is authorized, but the expected observation is missing. The lifecycle must remain incomplete rather than declare success.
An authorization never replaces observation.
Lesson scope
This lesson describes a control topology and the questions to document at each stage.
What this lesson does not demonstrate
It proves no execution, external observation, or completeness of a log.
Check question
What distinguishes an authorization from an outcome?
Choose an answer to read its feedback.
Local checklist
Find the break
Read a fictional chain and identify the missing stage.
This exercise checks no real log.
Sources and limitations
Sources and limitations
- Source repository
- https://github.com/SwissTokint/swisstokint-website
- Source reference
- codex/learning-hub-v3-autonomous-controls
- Content commit
- 29c88f79cee07a72804bc017b92fab9200fd3734
- Source version
- learning-v3
- Artificial Intelligence Risk Management Framework: Generative AI Profile
NIST-AI-600-1- Publisher
- National Institute of Standards and Technology (NIST)
- Version or date
- 2024-07-26
- Link verified on
- 2026-08-13
- Scope used
- Risk profile and candidate actions for generative AI systems.
- Limitation
- The profile certifies neither a control nor an agent.
- Artificial Intelligence Risk Management Framework (AI RMF 1.0)
NIST-AIRMF-1.0- Publisher
- National Institute of Standards and Technology (NIST)
- Version or date
- AI RMF 1.0, 2023-01-26
- Link verified on
- 2026-08-13
- Scope used
- Govern, Map, Measure, and Manage functions for structuring a risk lifecycle.
- Limitation
- The framework remains voluntary and general.