Evidence note · reviewed 29 July 2026


An agent is authority delegated to software.

The central question is not whether it can plan. It is which identity may use which tool, on which object, for how long, at what cost, with whose approval.

Minimum action contract

Identity
named human and agent seat
Scope
exact objects and purpose
Tools
allow-list and argument bounds
Budget
time, cost, steps and rate
Gate
human approval before impact
Receipt
request, result and state change
Stop
immediate revocation path
Replay
evidence sufficient to reconstruct

Separate advice from action

Drafting, searching and proposing are lower-authority modes. Sending, approving, purchasing, deleting, publishing or changing production state require narrower grants and explicit gates. The model must not infer that authority from conversational tone.

Evidence boundary: an audit log records behaviour; it does not make over-broad authority safe.

Inspect the full control plane →

Define the stop control before the first tool.

Discuss a governed workflow