Agents you name, limit and stop.
Most trouble with agents starts the same way: a key gets pasted into a script. After that nobody can say which machine did what, or on whose say-so. Give each agent its own name and those questions have answers: its owner, what it may touch today, and how to stop it. Stopping takes effect on its very next request.

A name of its own, not a borrowed key
Give an agent an identity of its own and it stops signing in as a person. It is written down the first time it appears and keeps that one name however often its keys are replaced. Every sign-in is placed in exactly one organization before anything else is read. So one customer's settings can never be reached while deciding about another's.
How an agent gets a nameIt can never do more than its owner
What an agent may do is the overlap between two lists. One is what somebody approved it to do, the other is what its owner may do at this moment. The second list is looked up again, not remembered from when the agent was set up. Take somebody's access away and their agents lose it with them, without anybody having to remember a second job.
What an agent may do
Anything irreversible stops and waits
Deploying, publishing, merging, sending something to a customer and changing how data is stored cannot be taken back wherever they run. An agent that asks for one of those gets a reference number instead of a result, and a named human decides.
How approvals workAssigned to both, on the same line
When an agent acts, the line is assigned to both: the machine that did it, and the person whose authority it was using. Not the machine twice. Every tool it reaches is written down with what it asked for, what came back, and how long it took. A call that was refused is written down as a refusal rather than as a quiet nothing.
What the record holdsA sign-in that ends on its own
A sign-in for a person's terminal expires sooner the more it can do. Seven days for full access, thirty for running a project, ninety for read-only. A sign-in for a machine has a length you choose. It can also be held to particular countries or networks on top of your organization's own rules.
How sign-ins are limitedRevoking works on the next request
Stop an agent and the next thing it asks for is refused, with a message saying it was stopped rather than mistyped. Being honest about the limit: this stops what comes next. It does not undo what the agent already did, and no product can. That is why anything irreversible waits for a named human in the first place.

Ask us what governing your first agent would take.
Also in Governance
- ApprovalsAnything that cannot be undone is assigned to a human.Read the page
- Audit trail and evidenceWho did what, on a sealed record, exported when someone asks.Read the page
- Agent identityA person lets an agent in, and can stop it again.Read the page
- What an agent may doIt never reaches further than its owner.Read the page
- Agent sign-insA sign-in expires sooner the more it can do.Read the page
- Approved modelsWhich models may run, who approved each one, and what it left behind.Read the page
- Scans and approved packagesApproved packages at the exact version, checked when used.Read the page