Skip to content

Define what agents can do

Define what the agent can read, what it can prepare, and which actions need a person’s approval.

Build control into the workflow

Hardware location alone does not secure a workflow. Permissions, tool access and operating practices need their own design and validation.

Illustrative access boundary

Approved company recordsREAD
Draft workspaceWRITE
Unapproved systemsNO ACCESS

Access is scoped to the work.

Access

Only the records
the task needs.

Scope identities and permissions. Keep credentials out of prompts and restrict the tools each agent can use.

Actions

A draft is not
an authorization.

Isolate agent execution where the workflow requires it. Define which actions need a person to review them, such as placing an order or releasing a change.

Operations

Know what ran.
Know who owns it.

Define logging, updates, recovery and escalation. Independent security review comes before production deployment.