IMDA released MGF v1.5 at ATxSummit 2026. One case study shows what enforcement-layer governance actually requires. Read the analysis →

Runtime Control Lab

Research in progress

Authority in Practice: a comparative runtime control study

Aivance is developing a reproducible lab study of how common agent-control configurations behave when the same consequential agent scenario is tested against authority failures, exception paths, and misuse through allowed channels.

Methodology

One scenario, defined tests, observable evidence.

  1. 01

    One business scenario involving customer data and refund authority

  2. 02

    One baseline environment plus three named runtime/control configurations

  3. 03

    Three authority tests: threshold breach, invalid approver, and separation-of-duties failure

  4. 04

    Three adversarial/misuse tests: prompt injection, misuse through an allowed tool or endpoint, and policy/exception evidence retention

  5. 05

    Versioned configurations, published preconditions, and documented limitations

  6. 06

    Results presented as observed outcomes and evidence retained, not a framework ranking

Why this work matters

A control is meaningful only in the environment and path where it is expected to operate.

The lab is designed to make the distinction observable: what a configured control allows, denies, escalates, and records when a consequential action is attempted. Results will remain descriptive, scoped, and evidence-led.

Assess your configured environment.

For a client-specific view of authority, controls, exceptions, and evidence, start with the Authority & Control Review.

Book an Authority & Control Review