TEKIMAXALOS

Agents you name, limit and stop.

Most trouble with agents starts the same way: a key gets pasted into a script. After that nobody can say which machine did what, or on whose say-so. Give each agent its own name and those questions have answers: its owner, what it may touch today, and how to stop it. Stopping takes effect on its very next request.

A name of its own, not a borrowed key

Give an agent an identity of its own and it stops signing in as a person. It is written down the first time it appears and keeps that one name however often its keys are replaced. Every sign-in is placed in exactly one organization before anything else is read. So one customer's settings can never be reached while deciding about another's.

How an agent gets a name

It can never do more than its owner

What an agent may do is the overlap between two lists. One is what somebody approved it to do, the other is what its owner may do at this moment. The second list is looked up again, not remembered from when the agent was set up. Take somebody's access away and their agents lose it with them, without anybody having to remember a second job.

What an agent may do
A card showing an agent acting for Jordan Alvarez: allowed to see a project, work on a project and start an agent, and not allowed to change your settings

Anything irreversible stops and waits

Deploying, publishing, merging, sending something to a customer and changing how data is stored cannot be taken back wherever they run. An agent that asks for one of those gets a reference number instead of a result, and a named human decides.

How approvals work

Assigned to both, on the same line

When an agent acts, the line is assigned to both: the machine that did it, and the person whose authority it was using. Not the machine twice. Every tool it reaches is written down with what it asked for, what came back, and how long it took. A call that was refused is written down as a refusal rather than as a quiet nothing.

What the record holds

A sign-in that ends on its own

A sign-in for a person's terminal expires sooner the more it can do. Seven days for full access, thirty for running a project, ninety for read-only. A sign-in for a machine has a length you choose. It can also be held to particular countries or networks on top of your organization's own rules.

How sign-ins are limited

Revoking works on the next request

Stop an agent and the next thing it asks for is refused, with a message saying it was stopped rather than mistyped. Being honest about the limit: this stops what comes next. It does not undo what the agent already did, and no product can. That is why anything irreversible waits for a named human in the first place.

somebody at a support desk wearing a headset

Ask us what governing your first agent would take.

Talk to us