Illustrative only - not an engagement finding
AI Can Trigger a System Action That Was Not Approved
Critical
See where this finding applies on the diagrams: model output path · bounded output handling · CP5 AI-call boundary
Illustrative only - not an engagement finding
AI Can Trigger a System Action That Was Not Approved
- Business summary
- An AI response is untrusted text, not permission to act. The application must never turn it directly into an email, database change, file deletion, paid operation or other system action. Before anything happens, server-side rules must check the signed-in user, the affected customer, the requested action and any required human approval.
- Assessment profile
- Expected fix Verification
-
-
Expected fix Keep every operation behind application code Background worker and server-side service adapters: Give Azure OpenAI no credentials and no direct route to tools or connected services.Verification Confirm the model cannot act directly The model has no credential or connection that can invoke a tool or connected service.
-
Expected fix Allow only defined actions Worker action-selection code: Match a checked model response to a fixed list of actions and permitted fields.Verification Reject unsupported actions Unknown actions, destinations and values fail before anything is sent, changed or charged.
-
Expected fix Take customer and destination details from the server FastAPI sign-in context and worker jobs: Set the customer, destination and permitted values from trusted server data, not from the model response.Verification Ignore model-proposed scope changes A customer, destination or value proposed by the model cannot replace the trusted server value.
-
Expected fix Check permission immediately before acting Server-side action and data-access code: Recheck the signed-in user and customer immediately before each operation.Verification Deny the action at the final boundary An otherwise valid action with the wrong customer or user permission is denied immediately before execution.
-
Expected fix Require accountable approval FastAPI review workflow and worker action state: Require a named person's recorded approval before any external, irreversible or high-impact operation.Verification Stop before high-impact work Every external, irreversible or high-impact test action waits for recorded human approval.
-
Expected fix Record who requested and approved the action Azure Monitor and application audit logs: Record the user, requested action, approval, enforcing code and outcome without personally identifiable information (PII), document content or model output.Verification Keep actions traceable The audit trail identifies the user, request, approval, enforcing code and outcome without storing PII or document content.
-