Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› Pre-Run Control
Governance, Ownership & Risk

Pre-Run Control

← Back to Glossary
By NHI Mgmt Group Updated October 11, 2026 Domain: Governance, Ownership & Risk

Pre-run control is governance applied before an unattended job executes, rather than after output appears. For scheduled agents, it covers identity scope, approved inputs, side-effect limits, and ownership so that the runtime inherits a safe boundary instead of improvising one.

What Pre-Run Control Actually Governs

Pre-run control is the discipline of setting the boundary before an unattended job starts. The point is not to watch output and react later, but to decide in advance what the job may access, what it may change, and who owns the result if it behaves unexpectedly.

That makes the term broader than scheduling alone. A pre-run control can include approved inputs, execution scope, side-effect limits, rollback assumptions, and the identity or authority boundary inherited by the runtime.

Why Pre-Run Control Matters for Automated Execution

Unattended jobs are often granted more trust than interactive workflows because they run at scale and with less human supervision. Without a pre-run boundary, a scheduled task can turn a small configuration mistake into a repeated security event, a repeated data exposure, or a repeated operational failure.

Pre-run control matters because it shifts assurance left in the execution chain. Instead of relying on post-execution review to catch harmful behaviour, the organisation decides up front what an acceptable execution envelope looks like and prevents the job from starting outside it.

Core Elements of a Pre-Run Boundary

A useful pre-run control usually combines several checks. The first is identity scope, meaning the job starts only with the access needed for its function. The second is input control, meaning the job receives known-good data, parameters, or prompts. The third is side-effect control, meaning the job is limited in what it can write, delete, publish, or invoke.

Ownership is the fourth element. An unattended job should not be treated as ownerless infrastructure, because ambiguity makes it hard to approve changes, investigate failures, or revoke access when the job is retired. If the execution boundary is unclear, the runtime may inherit permissions that are broader than the task actually requires.

How Pre-Run Control Differs from Post-Run Review

Post-run review asks whether the job did the right thing after it has already acted. Pre-run control asks whether the job should be allowed to act at all under the current conditions. Both matter, but they solve different problems.

Pre-run control is strongest when the risk is predictable and preventable, such as overbroad permissions, unsafe inputs, or unmanaged side effects. Post-run review is still useful for detection and audit, but it cannot undo all of the damage caused by an unnecessary execution.

Risk and Threat Considerations

Pre-run control fails when organisations assume that a scheduled job is inherently safe simply because it is automated. If the job can start with stale approval, excessive access, or unvalidated inputs, repeated execution can amplify a minor mistake into broad and persistent exposure.

Failure mechanism: The job inherits too much authority, consumes unsafe parameters, or performs side effects that were never bounded before launch. That creates a repeatable path for misuse, accidental damage, or abuse of trust in unattended execution.

Impact: The result can be data modification, credential or secret exposure, unauthorized actions, or uncontrolled downstream changes that are harder to contain because the job runs without direct supervision.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-6 — Least PrivilegePre-run control depends on limiting what unattended jobs may access before execution.
IA-5 — Authenticator ManagementPre-run control often depends on managed secrets or tokens used by the job at launch.
CM-3 — Configuration Change ControlPre-run approval is a configuration gate for execution parameters and runtime changes.
Recommendation — Apply least-privilege access to job identities before allowing scheduled execution. Rotate and validate credentials used by automated jobs before they are allowed to run. Require change approval for job configuration and execution-boundary updates before release.
CIS Controls v8CIS-5 — Account ManagementAutomated jobs rely on accounts whose access must be provisioned and governed before execution.
Recommendation — Review and restrict automation accounts before scheduled tasks are enabled.
NIST CSF 2.0PR.AA-01 — Identity Management, Authentication and Access ControlPre-run control is about defining and enforcing access before a job starts.
Recommendation — Define and enforce access boundaries for automated jobs before execution begins.

Practitioner Guidance

Governance implication: Treat pre-run control as an approval boundary, not a logging exercise. The key question is whether the execution context is safe before start, including who owns the job, what it may touch, and what must be true for it to proceed.

What to watch for: Reused automation roles, broad default inputs, and jobs that can produce external side effects without a clear pre-execution check are common signals that the control boundary is too loose.

Practitioner takeaway: If you cannot describe the job’s allowed scope before it runs, you have not controlled the run, only the aftermath.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org