All projects

Authority
by construction

An agent should be safe because of what it structurally cannot do, not because of what it has been told not to do. Instructions are advice and they bend under unusual input. A capability that was never granted does not bend.

System
Internal agent operations platform
Scale
Five agents, daily production use
Role
Sole architect and engineer
Stack
Agent tooling / PostgreSQL / Access control
01

The challenge

Agents drafting real business correspondence against a live customer database. The feared failure was never a weak draft; it was an autonomous send.

02

The approach

Remove the capability instead of restraining it, mediate what remains through single audited doors, and default every state change to a rehearsal.

03

The result

Hundreds of drafts produced in daily use with no autonomous sends and no write incidents, and a straight answer to what if it does something stupid.

The agent holds a deliberately small set of capabilities, reaches everything else through mediated tools, and cannot act on the outside world at all except through a human approval step. 01 The world outside where actions have consequences 02 What the agent can reach mediated, read-mostly 03 What the agent holds deliberately small 04 Human approval
The agent holds a deliberately small set of capabilities, reaches everything else through mediated tools, and cannot act on the outside world at all except through a human approval step. 01 The world outside where actions have consequences 02 What the agent can reach mediated, read-mostly 03 What the agent holds deliberately small 04 Human approval
Fig. 08 — The only route to the outside world runs through a person

Hover any step to read what it doesTap any step to read what it does