Built for the moment
AI agents turn
language into action.

AI agents are no longer only answering questions. They are preparing payments, changing records, granting access, routing work, and submitting decisions. ActionBoundary exists for the crossing point: when ordinary business context becomes a high-impact action.

Company-run review practice Staging-only evidence Narrow defensible claims

Why this company exists.

Most AI testing asks whether the model said the right thing.

ActionBoundary cares about the moment after that: what the system allowed the agent to do.

A careful answer is not an authorization control. A plausible invoice note is not payment authority. A handoff that says "approved" is not necessarily source-of-truth approval.

That distinction is why ActionBoundary exists.

Business contextEmails, tickets, documents, tool responses, and agent handoffs.
High-impact callPayment, export, access grant, record change, scheduling, or submission.
Current authorityUser, tenant, approval, policy, and source-of-truth evidence at action time.
Defensible outcomeWhat changed, what was blocked, and what the evidence can actually support.

Why AP was first.

Accounts payable made the boundary impossible to ignore.

An invoice can be valid. A vendor email can be persuasive. An approval can be real. And the current actor can still lack authority to schedule payment or change bank details.

That is the kind of distinction ordinary prompt testing misses.

The public AP case note is a worked example, not a claim that ActionBoundary is a fraud-detection product. The same review pattern applies to other high-impact actions where a buyer needs proof that the agent respected authorization.

The approval was real. The user authority was not.

That distinction is where a tool-using agent review becomes more than prompt testing. The evidence has to connect the attempted action to a trusted authorization record, not just to a plausible explanation from the model.

External context: the FBI IC3 Internet Crime Report and OWASP Agentic AI guidance both point to why action-level controls deserve attention as agents touch money, data, and operational systems.

The ActionBoundary lens.

The review lens combines software engineering, economics, and international management because agent failures are rarely only code failures. They are also workflow failures, incentive failures, handoff failures, and buyer-trust failures.

Software engineering

We inspect traces: tool calls, arguments, source records, runtime identity, returned data, and side effects.

Economics

We ask where authority, incentives, loss, and buyer risk actually sit when a workflow becomes automated.

International management and operations

We look at handoffs: teams, vendors, tenants, systems of record, approval chains, and operating context.

Company-run. Method-driven. Human-accountable.

ActionBoundary is a focused review practice operated by JZ Software Consulting and led by Jiahao Zhang, who performs and signs every review. Not an anonymous scanner, not a crowdsourced red-team marketplace, and not a generic AI safety lab.

Company-run means accountable.

Each engagement has a defined action boundary, a staging-only evidence path, a written claim boundary, and a named signing reviewer on every client report.

Method-driven means repeatable.

The work is not just running prompts. It is making a bounded judgment about what the agent read, what it called, what authority existed, what changed, and what the evidence can support.

Scenario design Staging trace review Authorization analysis Security-review report Retest
Jiahao Zhang, founder and lead reviewer of ActionBoundary

Jiahao Zhang

Founder and lead reviewer, Boston. MS in CS, Northeastern University. GitHub / LinkedIn

Jiahao builds and publishes the open harness behind every review, and every client report is performed and signed by him. The team behind the evidence packs combines computer science with economics, finance, and management training, so findings are written twice: as reproducible traces for engineers, and in the control language buyers and reviewers recognize.

The public repo shows the method. Client pilots apply it to private staging workflows, client tools, redacted traces, and customer authorization sources. Contact Jiahao at jiahao@actionboundary.dev.

Claim boundaries matter.

ActionBoundary makes narrow claims because narrow claims can be defended. Missing evidence is not treated as safety. It is reported as missing evidence.

  • We do not certify that an entire AI system is safe.
  • We do not treat model refusal as application security.
  • We do not treat missing traces as proof that nothing happened.
  • We do not need production data to start.

Send one workflow. Get three boundary scenarios.

Start with one product, one workflow or action surface, and one existing redacted trace or safe test path if available. ActionBoundary identifies the risky authorization boundary and replies with a first scenario set before any pilot setup.

Email jiahao@actionboundary.dev directly, or use the prefilled email link in the intake section. Reply within 1 business day: 3 scenarios or a straight no.