C3 Social Design Center

Search this site

Search pages, Verify ID...

日本語
← Control Assurance services

FOR EXECUTIVES, CISOs AND LEGAL TEAMS

Decide what AI may do, where it must stop and who has the final say.

Before an AI agent sends a message, calls an API, changes a configuration or places an order, define the conditions for delegation, the stop boundary, human escalation and the evidence needed afterwards.

Start free pre-screening →

Three perspectives on one control boundary

Executives and business owners

How much work should AI be allowed to do?

Separate actions the AI may complete automatically from actions that must return to an accountable person. Consider consequential external effects such as sending messages, changing settings and placing orders, not merely task completion.

CISOs and security leaders

Where must it stop?

Define a pre-execution stop when targets, authority, current state, approval, retry or recovery no longer match the agreed conditions.

Legal and compliance leaders

What should be recorded and escalated?

Retain who approved which object and version, what remains undecided and when the process returned to a person. C³ does not make the legal or policy decision on the customer's behalf.

Five conditions a responsible owner should decide

  1. 01Work to delegateIdentify the workflow and concrete actions with external effects.
  2. 02Conditions for delegationDecide which target, approval, authority and state conditions must be met before execution.
  3. 03Conditions requiring STOPIdentify uncertainty, target changes, mismatched state and excess authority that prohibit the proposed action.
  4. 04Conditions for human escalationDefine what must return to a person rather than allowing AI to continue deciding.
  5. 05Evidence to retainKeep the target version, declared conditions, approvals, observations and unresolved questions separate and traceable.

Three business scenarios

Customer email

Proposed action
Draft and send a response
Stop condition
No approval, changed recipient or changed body must prevent the send.
Evidence
Approver, recipient, approved content, target version, actual send result.

API or configuration change

Proposed action
Change a system setting through an agent
Stop condition
Do not execute if the target, authority or current state diverges from the declared scope.
Evidence
Target identifier, effective authority, before/after state, execution result.

Ordering and booking

Proposed action
Purchase a resource or change a reservation
Stop condition
Amounts, quantity and retry attempts outside the approved scope return to a person.
Evidence
Approval conditions, target, amount or quantity, observed external effect.

These are explanatory scenarios, not prescriptions for the customer's policies or actual inspection results.

Control observations

Freeze the target version, declared control, actual witness set and evidence. Describe separately where control was preserved, a counterexample occurred, evidence was insufficient or a path remained unobserved.

Delegation and execution authority

The observed result can support a human delegation decision, but it does not answer every policy question. Decision support is distinct from granting actual runtime permission. Final accountability remains with the customer's authorized people.

Choose the next step by evidence and maturity

These paths may be used separately. A design review never automatically becomes a formal inspection, and an inquiry never automatically becomes a paid engagement.

Free pre-screening

Free

Start from three short questions about the AI use, how fixed its rules are and its current state. The response helps select an appropriate next step.

Open the three-question screening →

AI Agent Control Design Review

JPY 30,000 excluding tax / one flow

When the rule is not yet fixed, turn documents and written explanations into implementation properties and conditions for future QA. No runtime inspection.

See the review scope →

Small-scope evidence check

JPY 50,000 excluding tax

When an existing response or state log can answer one bounded question, compare up to 20 agreed cases for one control without treating it as a runtime-path inspection.

See the small-scope plan →

Standard Control Condition Gap Check

JPY 600,000 excluding tax / standard scope

When a version and control are fixed and executable, observe the normal and changed-condition paths and retain counterexamples, UNDEFINED and missing scope separately.

See the formal inspection →

Formal inspection is bounded by agreed release, control, trial counts and evidence; separate conditions require a separate quote.

Public reference material

A source-code review sample is not evidence that an actual customer runtime effect was tested.

What this service does not establish

  • • Not legal advice or a guarantee of regulatory compliance.
  • • Not a guarantee of system-wide safety or an absence of incidents.
  • • Not third-party certification or conformance certification.
  • • Does not automatically issue a release, deployment or runtime Permit from a verification result.
  • • Does not replace organization-wide governance, a security assessment, performance testing or an audit.

No credentials, raw production data or detailed confidential files are requested for the initial pre-screening.

doc_id: C3-WEB-CONTROL-ASSURANCE-DECISION-EN-0.1 / version: 0.1.0 / status: REVIEW_REQUIRED / last_updated: 2026-10-11