An organization deploys agentic AI systems that autonomously query external sources, make decisions, and trigger actions across business workflows. In one case, an agent exceeds its intended authority by chaining actions across systems without human approval. Leadership wants innovation but defensible governance.
What is the MOST appropriate control to establish FIRST?
A. Continuous monitoring of agent activity with real time alerting
B. Strong authentication and API rate limiting for agent actions
C. Clearly defined authority boundaries and risk ownership for agents
D. Periodic audits of agent decisions and outcomes