Leadership wants an AI agent to flag renewal risk and send recovery emails automatically. What would you allow it to do?

Instruction: Describe permitted data, action authority and the specific message type. Treat NIST guidance as a risk framework; the proposed CSM controls are practical design choices, not a mandatory NIST workflow.

Context: It distinguishes internal assistance from customer-facing authority and allows useful bounded automation while exposing failure and stop conditions.

Updated

Official answer available

Read the opening below, then unlock the full answer and practical guidance.

I'd separate detecting possible risk, drafting a response and taking an external action. The agent could initially gather permitted account signals and draft an internal summary with sources, uncertainty and the reason for a risk flag. A CSM would verify important facts and choose the next action...

Related Questions