{
  "aliases": [],
  "canonicalUrl": "https://xn--mwe.com/controls/catalog/bounded-action-tiering/",
  "claimIds": [],
  "claimStatus": "PROJECT TECHNICAL PROPOSAL",
  "correctionStatus": "CURRENT K05 RELEASE",
  "currentnessQualification": "K05 point-in-time review of selected current official and first-party records completed on 2026-08-15. The review verifies publication text and status only; no public runtime monitor, live-host observation, facility-specific legal opinion, license determination, or operational effectiveness claim is created.",
  "description": "AUT-01 vendor-neutral control objective, evidence, failure indicators, assurance links, and applicability-qualified source mappings.",
  "id": "AUT-01",
  "lastReviewed": "2026-08-16",
  "name": "Bounded autonomous action tiering",
  "publicPath": "/controls/catalog/bounded-action-tiering/",
  "releaseId": "K12-2026-08-16",
  "releaseVersion": "2.1.0",
  "researchCutoff": "2026-08-16",
  "shortAnswer": "Separate observe, recommend, contain, protect, restore, and external-effect tiers; authorize tools and outcomes independently at each tier.",
  "sourceRevalidatedAt": "2026-08-15T23:00:00Z",
  "title": "Bounded autonomous action tiering",
  "topic": "critical-datacenter-protection",
  "type": "control"
}
