Results show that compliance-critical APA requires architectural governance rather than prompt-level reliance on LLM discretion, and proposes Governed APA, a runtime decision architecture that bounds LLM autonomy through schema-validated inputs, a closed action space, a policy-derived floor guardrail, and a deterministic fallback.
Abstract
Agentic Process Automation (APA) extends Robotic Process Automation by delegating workflow construction and runtime decisions to Large Language Model (LLM) agents. In regulated business processes, this autonomy creates a specific safety risk: an LLM may recognize elevated risk while still failing to trigger the human approval required by policy. We propose Governed APA, a runtime decision architecture that bounds LLM autonomy through schema-validated inputs, a closed action space, a policy-derived floor guardrail, and a deterministic fallback. We formalize the governed decision and establish a floor-safety property ensuring that the executed action cannot under-escalate below the policy-mandated minimum. The architecture is evaluated on a structured employee-onboarding case study with 166 profiles and explicit human-in-the-loop (HITL) ground truth. We compare a deterministic baseline, an ungoverned LLM, and a guarded LLM using two local models, Qwen2.5 and llama3.1. Ungoverned Qwen2.5 identified elevated risk but failed to escalate any of the 43 sensitive cases to mandatory human approval, yielding HITL recall equal to 0. Ungoverned llama3.1 showed the opposite failure mode, achieving full recall but producing unnecessary human-approval escalations. With the floor guardrail active, Qwen2.5 HITL recall increased to 1.0, llama3.1 recall remained 1.0, and inter-run stability of the compliance decision increased from 0.73 to 1.0 for Qwen2.5. On this dataset and configuration, no false-positive HITL escalation was introduced for Qwen2.5. These results show that compliance-critical APA requires architectural governance rather than prompt-level reliance on LLM discretion. The policy-derived floor guardrail enforces the floor-safety property and prevents silent under-escalation. The guarantee is local: it constrains the compliance routing decision under validated inputs and a trusted policy, and does not cover input corruption, policy errors, extraction failures, prompt injection, downstream tool misuse, or end-to-end workflow correctness. The evaluation is a single-process, two-model proof of concept, and generalization to other regulated workflows is a hypothesis for future validation.
Agentic AI-enabled automation cannot be safely deployed in high-stakes environments on probabilistic reasoning alone. A recurring risk is epistemic drift: as reasoning deepens, system behavior may move away from subject-matter-expert constraints for safe operation. This paper presents BRaVeS, a bounded reasoning and sa...
S. Ramaswamy, Deveeshree Nayak· Journal of Intelligent and R...· 0 citations
Agentic AI can interpret information, plan, make workflow decisions, and use enterprise tools. Yet technical capability does not establish authoritative meaning, legitimate process state, organisational permission, or accountable execution. The challenge is to preserve adaptability while ensuring that consequential act...
PolicyGuide compiles each domain policy into a workflow graph and invokes a proactive verifier at user-turn boundaries and finds the lowest observed attack-success rate under adversarial users and the strongest procedural compliance in an author-designed workflow-level validation.
Seongjae Kang, Taehyung Yu, Sung Ju Hwang· 2 citations
Deployed large language model (LLM) agents are now being used to interface with external tools, fetch information, run code, interact with user data and help with decision making at the workflow level. Therefore, their safety issues are not only related to the underlying model, but also to tool permissions, prompt desi...
Aakash Abhay Yadav, Shashank Shelat, B. Hinduja et al.· International Conference on...· 0 citations
Agentic artificial intelligence requires safeguards that remain effective across trajectories rather than only at individual decisions. This study introduces MARIS-TRA, a hierarchical temporal runtime assurance extension of Controlled Agentic AI Systems. A compact, auditable fragment of Signal Temporal Logic (STL) prov...
Tymoteusz Miller· Machine Learning and Knowled...· 0 citations
Agentic workflows now make consequential decisions in regulated settings, and the governance placed around them is almost entirely step-scoped: input-output classifiers, per turn rails, and span-level evaluators. The policies organizations actually hold, such as referral thresholds, authority limits, and review require...
Ashwini Kurady, S. Grandhi, R. Gupta et al.· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.