Yesterday we covered the translation layer: how software exposes its capabilities to agents as structured actions instead of UI.
But there's an obvious question. If an agent can call "create an invoice" or "delete a record," what stops it from doing something it shouldn't?
That's where permissions and approvals come in.
Permissions define which actions an agent is allowed to reach. Not every agent needs every capability. A support agent might search records and draft responses. It has no business touching billing. The team decides exactly which parts of the product each agent can access, down to the individual action.
Approvals handle the gray areas. Some actions are safe to run freely. Others — refunds, deletions, anything irreversible — pause and wait for a human. The agent prepares everything, presents the context, and the human makes the call. Control stays with the team, not the model.
This is the difference between giving an agent a login and giving it a job. A login inherits the human's full power. A permissioned action grants only what's needed, with oversight where it counts.
Agents that can act are useful. Agents that can act within bounds are deployable.
What's one action in your product you'd want an agent to take — and one you'd want it to ask about first?
Top comments (0)