Allow safe work
Read-only, non-sensitive information, operational status queries, and order retrieval are examples of actions that may be allowed automatically when the policy and context permit them.
Approve consequential work
High-value refunds, sensitive account changes, or production-impacting actions may need an authorized reviewer. Approval should be bound to the exact request and consumed deliberately.
Deny prohibited work
Disallowed administrative operations and actions explicitly prohibited by policy should stop before they reach the upstream tool.
Policy needs context
A policy should evaluate more than the tool name. Depending on the implementation, useful inputs can include requesting identity, agent identity, tool, action, arguments, context, and risk level.
This threshold is an example policy, not a claim about a fixed default. The important idea is that autonomy is explicit and controlled.
Good AI governance is not about preventing agents from acting. It is about making autonomy explicit and controlled.