Open Access

Human-in-the-Loop Control Planes for Cortex Agents: Policy-Driven Escalation, Approval, and Evidence Capture

4 Independent Researcher, USA
4 Independent Researcher, USA

Abstract

Purpose. Enterprise agents can accelerate anomaly triage and regulated reporting, yet ordinary access control, prompt instructions, and post-hoc traces do not define a complete authorization contract for consequential actions. This study develops PAVE-CP, a vendor-neutral control plane that determines when an agent must escalate, which evidence must accompany the request, who may approve, and how the resulting decision is enforced and recorded.

Design/methodology/approach. Following design-science research, requirements are derived from human–automation research, security principles, policy-as-code, provenance, AI-governance sources, recent agent-authorization work, and documented Cortex Agents interfaces. The artifact comprises a canonical action envelope, policy decision point, graded evidence model, approval broker, exact-action tokens, governed execution gate, postcondition verification, and a tamper-evident event ledger. Evaluation combines one million randomized policy-state checks, 20,000 end-to-end authorization checks, seven seeded mutations, and a reproducible discrete-event simulation of one million proposed actions.

Findings. The reference controller produced no structural mismatch in the exercised randomized and end-to-end state spaces and detected all seven seeded mutations. Under the stated synthetic assumptions, PAVE-CP routed 16.54% of proposals to review, preserved 81.78% bounded autonomy, and produced 0.36 modeled high-impact unsafe commits per 10,000 proposals, compared with 129.79 for role-based autonomy and 14.92 for blanket human review. Median latency was 2.34 seconds, while the approval-bound 95th percentile remained 237.10 seconds.

Originality, implications, and limits. The contribution is an externally enforceable commit protocol, not another prompt guardrail or observability dashboard. It binds policy, evidence, human authority, exact parameters, freshness, separation of duties, execution, and audit evidence into one verifiable control object. The Cortex mapping shows how rapid read-only investigation and drafting can coexist with explicit authorization for regulated publication and high-impact state change. Quantitative results are synthetic design-science evidence, not production telemetry or a compliance claim.

Keywords

References

Hevner, A.R., March, S.T., Park, J. and Ram, S. (2004), “Design science in information systems research”, MIS Quarterly, Vol. 28 No. 1, pp. 75–105. https://doi.org/10.2307/25148625.
Peffers, K., Tuunanen, T., Rothenberger, M.A. and Chatterjee, S. (2007), “A design science research methodology for information systems research”, Journal of Management Information Systems, Vol. 24 No. 3, pp. 45–77. https://doi.org/10.2753/MIS0742-1222240302.
Gregor, S. and Hevner, A.R. (2013), “Positioning and presenting design science research for maximum impact”, MIS Quarterly, Vol. 37 No. 2, pp. 337–355. https://doi.org/10.25300/MISQ/2013/37.2.01.
National Institute of Standards and Technology (2023), Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1, Gaithersburg, MD. https://doi.org/10.6028/NIST.AI.100-1.
National Institute of Standards and Technology (2024), Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1, Gaithersburg, MD. https://doi.org/10.6028/NIST.AI.600-1.
European Parliament and Council of the European Union (2024), Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence, Official Journal of the European Union, 12 July 2024.
International Organization for Standardization and International Electrotechnical Commission (2023), ISO/IEC 42001:2023, Information technology—Artificial intelligence—Management system.
International Organization for Standardization and International Electrotechnical Commission (2023), ISO/IEC 23894:2023, Information technology—Artificial intelligence—Guidance on risk management.
International Organization for Standardization and International Electrotechnical Commission (2023), ISO/IEC 5338:2023, Information technology—Artificial intelligence—AI system life cycle processes.
Parasuraman, R., Sheridan, T.B. and Wickens, C.D. (2000), “A model for types and levels of human interaction with automation”, IEEE Transactions on Systems, Man, and Cybernetics—Part A, Vol. 30 No. 3, pp. 286–297. https://doi.org/10.1109/3468.844354.
Bainbridge, L. (1983), “Ironies of automation”, Automatica, Vol. 19 No. 6, pp. 775–779. https://doi.org/10.1016/0005-1098(83)90046-8.
Goddard, K., Roudsari, A. and Wyatt, J.C. (2012), “Automation bias: a systematic review of frequency, effect mediators, and mitigators”, Journal of the American Medical Informatics Association, Vol. 19 No. 1, pp. 121–127. https://doi.org/10.1136/amiajnl-2011-000089.
Amershi, S., Weld, D., Vorvoreanu, M., Fourney, A., Nushi, B., Collisson, P., Suh, J., Iqbal, S., Bennett, P.N., Inkpen, K., Teevan, J., Kikin-Gil, R. and Horvitz, E. (2019), “Guidelines for human–AI interaction”, Proceedings of CHI 2019, Paper 3. https://doi.org/10.1145/3290605.3300233.
Shneiderman, B. (2020), “Human-centered artificial intelligence: reliable, safe and trustworthy”, International Journal of Human–Computer Interaction, Vol. 36 No. 6, pp. 495–504. https://doi.org/10.1080/10447318.2020.1741118.
[15] Saltzer, J.H. and Schroeder, M.D. (1975), “The protection of information in computer systems”, Proceedings of the IEEE, Vol. 63 No. 9, pp. 1278–1308. https://doi.org/10.1109/PROC.1975.9939.
[16] Rose, S., Borchert, O., Mitchell, S. and Connelly, S. (2020), Zero Trust Architecture, NIST Special Publication 800-207. https://doi.org/10.6028/NIST.SP.800-207.
Joint Task Force (2020), Security and Privacy Controls for Information Systems and Organizations, NIST Special Publication 800-53 Revision 5. https://doi.org/10.6028/NIST.SP.800-53r5.
OASIS (2013), eXtensible Access Control Markup Language (XACML) Version 3.0, OASIS Standard, 22 January 2013.
Open Policy Agent (2026), “Policy language and policy-as-code documentation”, available at: https://openpolicyagent.org/docs/policy-language (accessed 13 July 2026).
[20] Open Policy Agent (2026), “Decision logs”, available at: https://openpolicyagent.org/docs/management-decision-logs (accessed 13 July 2026).
Rundgren, A., Jordan, B. and Erdtman, S. (2020), JSON Canonicalization Scheme (JCS), RFC 8785. https://doi.org/10.17487/RFC8785.
World Wide Web Consortium (2013), PROV-O: The PROV Ontology, W3C Recommendation, 30 April 2013, available at: https://www.w3.org/TR/prov-o/.
World Wide Web Consortium (2021), Trace Context, W3C Recommendation, 23 November 2021, available at: https://www.w3.org/TR/trace-context/.
OpenTelemetry Authors (2026), OpenTelemetry Specification and Documentation, available at: https://opentelemetry.io/docs/ (accessed 13 July 2026).
Haber, S. and Stornetta, W.S. (1991), “How to time-stamp a digital document”, Journal of Cryptology, Vol. 3, pp. 99–111. https://doi.org/10.1007/BF00196791.
Yao, S., Zhao, J., Yu, D., Du, N., Shafran, I., Narasimhan, K. and Cao, Y. (2023), “ReAct: synergizing reasoning and acting in language models”, 11th International Conference on Learning Representations.
Liu, X. et al. (2024), “AgentBench: evaluating LLMs as agents”, 12th International Conference on Learning Representations.
Ruan, Y., Dong, H., Wang, A., Pitis, S., Zhou, Y., Ba, J., Dubois, Y., Maddison, C.J. and Hashimoto, T. (2024), “Identifying the risks of LM agents with an LM-emulated sandbox”, 12th International Conference on Learning Representations.
Debenedetti, E., Zhang, J., Balunovic, M., Beurer-Kellner, L., Fischer, M. and Tramùr, F. (2024), “AgentDojo: a dynamic environment to evaluate prompt injection attacks and defenses for LLM agents”, Advances in Neural Information Processing Systems, Vol. 37.
Turpin, M., Michael, J., Perez, E. and Bowman, S.R. (2023), “Language models do not always say what they think: unfaithful explanations in chain-of-thought prompting”, Advances in Neural Information Processing Systems, Vol. 36.
Yuan, A., Su, Z. and Zhao, Y. (2026), “AEGIS: no tool call left unchecked—a pre-execution firewall and audit layer for AI agents”, arXiv:2603.12621.
Wang, P., Li, Y. and Tian, Y. (2026), “Reframing LLM agent security as an agent–human interaction problem”, arXiv:2605.24309.
Snowflake Inc. (2026), “Cortex Agents”, Snowflake Documentation, available at: https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-agents (accessed 13 July 2026).
Snowflake Inc. (2026), “Cortex Agents Run API”, Snowflake Documentation, available at: https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-agents-run (accessed 13 July 2026).
Snowflake Inc. (2026), “Monitor Cortex Agent requests”, Snowflake Documentation, available at: https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-agents-monitor (accessed 13 July 2026).
Snowflake Inc. (2026), “AI Observability in Snowflake Cortex”, Snowflake Documentation, available at: https://docs.snowflake.com/en/user-guide/snowflake-cortex/ai-observability (accessed 13 July 2026).
Snowflake Inc. (2026), “Create and manage agents”, Snowflake Documentation, available at: https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-agents-manage (accessed 13 July 2026).
Snowflake Inc. (2026), “Cortex Agent versioning”, Snowflake Documentation, available at: https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-agents-versioning (accessed 13 July 2026).
Lee, J.D. and See, K.A. (2004), “Trust in automation: designing for appropriate reliance”, Human Factors, Vol. 46 No. 1, pp. 50–80. https://doi.org/10.1518/hfes.46.1.50_30392.
Parasuraman, R. and Riley, V. (1997), “Humans and automation: use, misuse, disuse, abuse”, Human Factors, Vol. 39 No. 2, pp. 230–253. https://doi.org/10.1518/001872097778543886.
Schneier, B. and Kelsey, J. (1999), “Secure audit logs to support computer forensics”, ACM Transactions on Information and System Security, Vol. 2 No. 2, pp. 159–176. https://doi.org/10.1145/317087.317089.
Zhang, H., Huang, J., Mei, K., Yao, Y., Wang, Z., Zhan, C., Wang, H. and Zhang, Y. (2025), “Agent Security Bench (ASB): formalizing and benchmarking attacks and defenses in LLM-based agents”, 13th International Conference on Learning Representations.
Brigham, N.G., Bagdasarian, E., Kohno, T. and Roesner, F. (2026), “Janus: a playground for user-involved agentic permission management”, arXiv:2607.01510.
Errico, H. (2026), “Autonomous Action Runtime Management (AARM): a system specification for securing AI-driven actions at runtime”, arXiv:2602.09433.
Zhang, Y.E. and Wang, G. (2026), “Towards human-centered agent authorization: a landscape analysis of commercial AI agents”, Extended Abstracts of the 2026 CHI Conference on Human Factors in Computing Systems, Article 684, pp. 1–10. https://doi.org/10.1145/3772363.3798851.
South, T., Marro, S., Hardjono, T., Mahari, R., Whitney, C.D., Greenwood, D., Chan, A. and Pentland, A. (2025), “Authenticated delegation and authorized AI agents”, arXiv:2501.09674.
OWASP GenAI Security Project (2025), “OWASP Top 10 for Agentic Applications for 2026”, available at: https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/ (accessed 13 July 2026).
Hu, V.C., Ferraiolo, D., Kuhn, R., Schnitzer, A., Sandlin, K., Miller, R. and Scarfone, K. (2014), Guide to Attribute Based Access Control (ABAC) Definition and Considerations, NIST Special Publication 800-162. https://doi.org/10.6028/NIST.SP.800-162.

Most read articles by the same author(s)

<< < 1 2 3 4 5 6 7 8 > >> 

Similar Articles

1-10 of 60

You may also start an advanced similarity search for this article.