What is Bounded Action?
Governance & ControlAn action an AI system may take on its own, inside limits written in advance: a refund cap, a discount ceiling, a price floor, a time window. The bound is what makes autonomy accountable rather than merely fast.
Why It Matters
Most autonomy debates are about whether an agent should act at all. The more useful question is what it may do, how much, and for how long. A refund under a cap inside a returns window is a routine service action. The same refund without the cap is a spending decision nobody approved.
Writing the bound is what turns a capability into an operating permission. It also produces the thing a finance team or an auditor will ask for: the limit that applied, the version of the policy, and who owned the decision.
How It Works
Four values describe a bound. The ceiling is the most the action can commit, in money or in scope. The window is when it may run, which for a return is the policy period and for a price change is the trading window. The eligibility rules decide which cases qualify, and the owner is the named person accountable for the action class.
Enforce them outside the model. A policy service evaluates the proposed action against the bound and returns allow, hold, or deny before execution, so the limit holds even when the prompt argues otherwise. Anything above the ceiling routes to a person with the evidence attached, and the verdict is recorded either way.
Where It Breaks
The first failure is a bound that lives in a prompt. Instructions describe intent and cannot stop an action; a limit that is not enforced by a service is a suggestion the model may weigh against a customer’s persistence.
The second is the shared credential. If the agent inherits an integration account with broad permissions, the ceiling is a number in a document while the system can still move any amount.
The third is stacking. A refund cap of two hundred dollars is not a bound if the same customer can trigger it ten times in an hour, or if a credit and a discount and a price override each sit under their own ceiling while the combined exposure has no owner. Bounds have to be evaluated per case and in aggregate.
The fourth is a bound nobody can inspect. If the limits live in application code with no record of what ran against them, answering “what could this agent have done last month” becomes a code review rather than a query.
How Flytebit Handles It
Bounds are configuration enforced by the runtime rather than text inside a prompt, evaluated per action and in aggregate, with the verdict and the policy version recorded for every attempt. Actions that move money also carry a defined reversal window, so the worst case is a corrected ledger rather than a loss. The industry application is on our E-commerce & Retail page, and the enforcement design is in Governing Agentic AI.