A regional health service's referral triage agent currently suggests appointment slots that a scheduler then books by hand, which adds a median of two days to each referral. The product owner wants the agent to book directly in the patient scheduling system. The security review board owns the decision to grant any automated write access to patient systems, and must formally accept whatever residual risk it approves. What should the architect present to the board?
- AThe two-day reduction and the scheduler hours it saves, since the board mainly needs to see that the benefit justifies the new access
- BA system prompt rule forbidding the agent to cancel or move bookings, so the board can approve broad write access as negligible risk
- CThe exact write actions requested, which records they can change, the controls scoping them and the residual risk, beside the two-day gain Correct
- DBroad write access with monitoring that alerts on unusual booking patterns, so the board can approve the monitoring plan in its place
Why A is wrong: This is tempting because the benefit is the reason for the change and every approval needs a business case. It is wrong because the board owns a risk decision, and a benefit-only framing gives it nothing about what the agent could change or how that is constrained, so it cannot knowingly accept the residual risk.
Why B is wrong: This is tempting because the instruction does describe the intended limit in plain language. It is wrong because a prompt instruction is not an enforced control on a compliance-relevant write path; the credential would still permit cancellations, so presenting the risk as negligible misstates what the board is accepting.
Why C is correct: Correct. A security board decides by weighing blast radius against benefit. Stating the specific actions, the records within reach, the structural controls such as a credential scoped to booking only, and the risk that remains lets the board make the acceptance decision it owns, with the clinical benefit shown alongside.
Why D is wrong: This is tempting because monitoring is a familiar control that security teams often ask for. It is wrong because alerting detects misuse after the fact instead of removing capability the agent does not need, and asking the board to approve monitoring in place of the access question hides the decision it actually owns.