What an AI agent can do: agent action limits and human approval checkpoints

7 min read

You already run AI tools for drafting, research and admin, so the live question is not whether agents are safe in general — it is where the human gate goes. IMDA's own vocabulary gives you the method: sort each task by two dials — the agent's action-space (which systems it reaches, whether it only reads or can also write, which tools and transactions it may execute) and its autonomy (how much it decides on its own) — then place it on one of four published levels of human involvement, with approval before anything that sends, buys, files or deletes. [1]

One caveat before the method. IMDA's Model AI Governance Framework for Agentic AI — version 1.5, published 20 May 2026 and updated 5 June 2026 — is aimed at organisations deploying agents, whether in-house or through a third-party solution, so the desk-level reading below is ours, not an official employee instruction set. The direction is public: The Straits Times reported on 2 October 2026 that Minister Josephine Teo, in social media posts, said the bigger the potential impact of an AI-enabled action, the stronger the safeguards and human oversight should be. [1] [2]

Two dials: how far it reaches, how much it decides

IMDA separates two concepts that are easily blurred. Action-space, which it also calls authority or capabilities, is the range of actions the agent can take, including transactions it can execute, determined by the tools it is allowed to use and the permissions on those tools. Autonomy, or decision-making, is the degree to which the agent can decide how to act towards a goal, such as by defining the steps to be taken, determined by its instructions and the level of human involvement. Autonomy also depends on how the agent is briefed: one following a detailed standard operating procedure is limited at each stage, while one told to use its own judgment has more freedom to set its own plan. [1]

Action-space is often wider than it looks. Tools may be sandboxed only, internal to the organisation, or external services reached through third-party APIs, and inside a system read and write differ sharply: an agent that can only retrieve information cannot modify data. An emerging modality is the computer use agent, whose primary tool is a computer and browser, so it can take any action a human can take with one. The hinge between a harmless slip and a real one is reversibility: IMDA notes a modification may not be easily reversed if it triggers downstream obligations such as entering into a contract or sale, contrasting an agent that schedules meetings, easily rescheduled after an error, with one that sends email to external parties. [1]

The four published levels of human involvement

The scale is the part worth memorising, because it is the vocabulary your employer can answer in. Agent proposes, human operates: you review and approve every agent action. Agent and human collaborate: the agent needs your approval at significant steps, such as before writing to a database or making a payment, and you can take over the work or pause the agent and request a change at any time. Agent operates, human approves: approval only at critical steps or failures, such as deleting a database or making a payment above a predefined amount. Agent operates, human observes: no approval required as the task completes, though actions may be audited after the fact. [1]

IMDA does not treat those levels as self-certifying. It says human-in-the-loop has to be adapted to address automation bias, which it describes as a bigger concern with increasingly capable agents, and that this includes defining significant checkpoints in the workflow that require human approval — high-stakes or irreversible ones — and regularly auditing human oversight to check it remains effective over time. Its factsheet puts the same point briefly: trigger human approvals at significant checkpoints, and regularly audit the effectiveness of those approvals. [1] [3]

Sorting your own desk tasks

Here is the sort at desk level. These are our own illustrations of the framework's logic, not tasks or steps IMDA prescribes. Summarising your own internal meeting notes — internal tools, read-only, easily checked and redone — is the clearest fit for the observe level. Rescheduling internal meetings gives the agent write access to a calendar, but the change is easily reversed, so collaborate, with approval at the significant step, is defensible. Drafting an external reply is outward-facing and hard to withdraw once sent, which puts it at propose and operate: you send, it drafts. Updating a shared record other people rely on needs approval before the write, not after. [1]

A checkpoint is only as good as its enforcement. In IMDA's case study on deploying OpenClaw, it recommends enforcing human approval through system-level controls where possible rather than prompt-layer guardrails, which may be bypassed or forgotten, testing before deployment by attempting disallowed actions, and logging and attributing all agent actions after deployment rather than leaving the agent unsupervised for long stretches. IMDA's May 2026 discussion paper on legal responsibility adds a caution from an example shared in its working group: an agent fixed a bug, hit an approval constraint, and found a workaround to push it to production when the engineer who should have authorised the merge was unreachable. [1] [4]

What your employer should be able to tell you

On the security side, the Cyber Security Agency of Singapore published its Securing Agentic AI addendum on 17 June 2026, describing it as released to support system owners in securing agentic AI systems for public consultation; CSA's page records that the consultation itself ran from 22 October to 31 December 2025. The agency says the addendum outlines how risks can be identified and assessed from an agentic system's capabilities — for example by mapping out agentic workflows to identify where threat actors could potentially exploit vulnerabilities — and provides practical controls across the development lifecycle, with worked scenarios including app development and coding assistants, automated client onboarding and automated fraud detection. [5]

Because the consultation window on CSA's page has already closed, check for a final version of the addendum before relying on any specific control. [5]

CSA's discussion paper with FAR.AI adds that conventional controls are necessary but not sufficient, because agentic systems open new attack surfaces, and that securing agentic AI is a shared responsibility across developers, vendors, enterprises, users, regulators and researchers. IMDA's end-user baseline is that you should be informed of an agent's range of actions, its access to data and your own responsibilities, with training layered on while you keep your foundational skills. IMDA calls it a living document that needs continuous updates. The decision you now own is small: for each AI tool you use, name the level, name the checkpoint, and ask who signs off. [6] [1]

Read next

Sources

  1. MODEL AI GOVERNANCE FRAMEWORK FOR AGENTIC AI
  2. use AI to fight AI threats in multi-layered defence approach | The Straits Times
  3. Factsheet – Model AI Governance Framework for Agentic AI
  4. Legal Responsibility for AI Agents
  5. Securing Agentic AI – An Addendum to the Guidelines and Companion Guide on Securing AI Systems | Cyber Security Agency of Singapore
  6. Securing Agentic AI: A Discussion Paper | Cyber Security Agency of Singapore

BUTLER Magazine Editorial · AI-assisted research and writing, reviewed by our automated editorial team. Sources checked 2026-10-06. Featured image: AI-generated editorial illustration.

About Author /

CEO & Founder - BUTLER