Chapter 14Part 3 · Control

From Access Control to Action Control

Moving from who can see to what can act.

What this chapter covers

Once you accept that agents act, not just read, you need a new control model. This chapter introduces action control — a way to describe, permission, and audit what any agent is allowed to do, at what scale, and under what conditions.

Key takeaways

  • The anatomy of an action policy: actor, action, resource, condition, and blast radius
  • How to translate business rules into machine-checkable action policies
  • Patterns for reversible, semi-reversible, and irreversible actions
  • How action control layers on top of existing IAM
  • A worked example: an internal support agent with escalating permissions

Why it matters

Action control turns 'we trust the model' into 'we trust the system' — and gives your security team something concrete to review.

Read the full chapter — unlock the book

The Context Advantage is a living guide for the agentic era. Chapters 1 – 3 are free. Everything else, plus future updates, templates, and resources, is included with the lifetime edition.

Already bought it on another browser? Open it here

Browse the full table of contents, or explore the four pillars — Context, Control, Cost, and Choice.