为智能体系统设计自主权边界,明确何时授权及如何管控。
Specifying the Delegated-Autonomy Boundary: Requirements Engineering for Agentic AI

- 提出代理授权记录与分级授权策略,规范智能体决策权限
- 定义六要素框架:目的、权限、信息、协调、保障与演进
- 适用于医疗、代码等高风险智能体开发场景
智能体系统不仅预测或推荐,还能规划、维持状态并在外部环境中自主行动,其自主程度可变。这带来了特定且未被充分关注的需求工程挑战:引入了‘委托自主边界’——即决定哪些任务可委托给系统、在何种分层权限下、需何种监督以及如何收回控制权。当前做法将这些决策隐藏于提示词、工具模式和运行时策略中,而它们实为需求层级的承诺。本文提出两个互补工具:一是代理合理性记录(AJR),帮助团队判断是否有必要使用智能体而非更简单方案;二是智能体委托策略(ADP),用于捕捉安全有效开发所必需的关键内容:目的、权限、信息、协调、保障与演化。关键在于,权限在ADP中以分层结构建模。通过两个对比案例进行说明:一个是涉及安全的关键医院出院协调智能体,另一个是自动化代码审查智能体。
原文摘要 · Abstract (English)
Agentic AI systems do not just predict or recommend; they plan, maintain state, and act in external environments with varying degrees of autonomy. This changes the requirements engineering problem in a specific and under-addressed way: it introduces what we call the delegated-autonomy boundary -- the set of decisions about what may be delegated to the system, under what graduated authority, with what oversight, and how control is returned. Current practices bury these decisions inside prompts, tool schemas, and runtime policies, even though they are requirements-level commitments. This paper proposes two complementary artifacts. First, an Agency Justification Record (AJR) helps teams decide when an agent is warranted over simpler alternatives. Second, an Agentic Delegation Policy (ADP) captures what must be specified for safe and effective development: purpose, authority, information, coordination, assurance, and evolution. Crucially, authority in the ADP is modelled as graduated, i.e., a tiered structure. We illustrate the framework with two contrasting examples: a safety-critical hospital discharge coordination agent and an automated code review agent.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。