ALLOWLow risk
APPROVALHigher risk
DENYForbidden

Allow safe work

Read-only, non-sensitive information, operational status queries, and order retrieval are examples of actions that may be allowed automatically when the policy and context permit them.

Approve consequential work

High-value refunds, sensitive account changes, or production-impacting actions may need an authorized reviewer. Approval should be bound to the exact request and consumed deliberately.

Deny prohibited work

Disallowed administrative operations and actions explicitly prohibited by policy should stop before they reach the upstream tool.

Policy needs context

A policy should evaluate more than the tool name. Depending on the implementation, useful inputs can include requesting identity, agent identity, tool, action, arguments, context, and risk level.

agent = support-agentaction = issue_refundamount = $10,000if amount > $1,000 → REQUIRE_APPROVAL

This threshold is an example policy, not a claim about a fixed default. The important idea is that autonomy is explicit and controlled.

KEY TAKEAWAY

Good AI governance is not about preventing agents from acting. It is about making autonomy explicit and controlled.