Position: The Clinical Action Envelope: Controlling Intervention Authority in Longitudinal Health AI Agents
Abstract
Longitudinal health AI is moving beyond static prediction toward systems that reason over patient trajectories and may recommend or trigger interventions. For such intervention-capable systems, predictive or conversational quality alone is insufficient: a model may produce a clinically plausible response or proposed action while that action remains unsafe to execute. We study this complementary reliability problem through the Clinical Action Envelope (CAE), a runtime clinical authorization model that maps each concrete proposed action and the preserved evidence from the interaction to allow, confirm, hold, or deny. CAE conditions executable authority on observable interaction history, uncertainty, action consequence, irreversibility, external impact, and available oversight without requiring a model-assigned psychiatric diagnosis. For systems that reason about patient trajectories and intervention outcomes, CAE provides an authorization layer that determines whether a proposed intervention or other consequential action may be executed. It introduces two safeguards: Action-Authority Contraction, which prevents worsening comparable conditions from increasing execution authority, and Controlled Restoration, which requires a policy-recognized authorizing event before authority can increase again. A hold suspends the side effect while preserving enough state for accountable clinical review. We illustrate CAE in longitudinal mental-health scenarios involving repeated checking, rapid consequential requests, and acute psychiatric crises, and define an evaluation design against static and context-aware authorization baselines. The resulting framework separates reasoning about a patient and proposed interventions from the authority delegated to an AI system to act on them.