Runtime Control Lab
Authority in Practice: a comparative runtime control study
Aivance is developing a reproducible lab study of how common agent-control configurations behave when the same consequential agent scenario is tested against authority failures, exception paths, and misuse through allowed channels.
Methodology
One scenario, defined tests, observable evidence.
- 01
One business scenario involving customer data and refund authority
- 02
One baseline environment plus three named runtime/control configurations
- 03
Three authority tests: threshold breach, invalid approver, and separation-of-duties failure
- 04
Three adversarial/misuse tests: prompt injection, misuse through an allowed tool or endpoint, and policy/exception evidence retention
- 05
Versioned configurations, published preconditions, and documented limitations
- 06
Results presented as observed outcomes and evidence retained, not a framework ranking
Why this work matters
A control is meaningful only in the environment and path where it is expected to operate.
The lab is designed to make the distinction observable: what a configured control allows, denies, escalates, and records when a consequential action is attempted. Results will remain descriptive, scoped, and evidence-led.
Assess your configured environment.
For a client-specific view of authority, controls, exceptions, and evidence, start with the Authority & Control Review.
Book an Authority & Control Review