TEKIMAXALOS

A person lets each agent in.

Every agent that turns up here has to say who its owner is. Until that person signs in and says yes, it holds no authority of its own. After that it acts in their name, the record says so, and one decision takes it away again.

hands signing a document

Written down the moment it appears

An agent is recorded the first time it asks for anything, before anybody has approved it. That is on purpose: an agent nobody wrote down is one nobody can stop. The page counts them for you and says plainly that an agent nobody approved acts for nobody. None of the rules you set on your people reach it.

Until its owner confirms it, it holds nothing

An agent names its owner when it registers, so there is no such thing here as one that belongs to nobody. Until that person signs in and confirms it, it is a row on your list with an empty acting-for cell. Everything that matters is shut to it. Nothing about it is a surprise, and nothing about it is urgent.

  • It can read: projects, documents, contacts, skills, and who is in your organization.
  • It cannot use a tool, run a model, or change anything at all.
  • The page that lists your agents counts the ones nobody has let in, so it is never a surprise.
A card for an agent nobody has approved: not approved, acting for nobody yet, and refused when it tries to use a tool

You sign in, you read it a code, it is yours

An agent asks to be let in and gets you a link. You open it, sign in as yourself, and the screen shows you a short code. Read that code back to the agent and it is yours: from then on it acts in your name and the record says so. The code appears only after you have signed in, so the agent never sees it until you hand it over.

  • A day to finish letting one in, and then the request is deleted.
  • A hundred requests an hour for the whole organization, five an hour for any one email.
  • Software that cannot open a browser goes the other way around. It shows YOU a six-character code, which you confirm while signed in as its owner. Ten minutes, and one use.
  • An agent cannot conjure an account for itself either. Setting one up with no sign-in at all is switched off.

One name, however often the keys change

Work an agent does in the background gets a fresh sign-in for each job. That is the right way around: a key that lives for one job is worth little if it leaks. The name does not change with it. So the record follows the agent across every run, and stopping it stops the agent rather than one key it happened to be holding.

Stopping one, and what stopping means

An administrator stops an agent with a written reason, and that reason goes on the record assigned to them. From its next request on, everything it asks for is refused, and the refusal says it was stopped. No agent can do this to another.

  • Stopping it stops everything under it: every key issued from it, and every agent it handed work on to.
  • Handing work on never buys more time. A chain of agents cannot outlive the sign-in the first one started from.
  • Remove its owner, or reduce what they are allowed to do, and it narrows with them within minutes.
A card for an agent that was stopped: revoked, stopped by Dana Okafor, and its next request refused

Stopped before it ever arrives

If a registration is withdrawn where it was issued, we write the stop down even for an agent that has never once contacted us. Its first request is then also its last. The record does not assign that to a colleague, because nobody here pressed anything.

The honest limit

Stopping an agent stops what it does next. It does not reach back and undo what it already did. It does not destroy the sign-in wherever that was issued: what it does is make us refuse it. That is why anything irreversible waits for a named human in the first place, rather than being something you have to catch afterward.

How approvals work

Walk through registering your first agent with us.

Talk to us