Three permission levels per action
Every tool an agent can use is marked auto, needs approval, or forbidden. Lookups and status answers are usually auto. Refunds, cancellations and outbound messages wait for a human click. Anything not listed is forbidden.
Drawn in the proposal
The permission table is part of the written proposal, so you decide the line before the build starts — not after an incident.
Everything logged
Each action writes one row: which role, which tool, when, the result, and who approved it. You can read anything the agent did and correct it.
Where a script beats an agent
If a plain script is safer than an agent for a task, we say so and build the script. Agents are for judgment within limits; scripts are for rules.
Questions
Can an agent issue a refund by itself?
Not the way we build them. Refunds sit behind an approval gate a human clicks, with a cap stated in the proposal.
Who sees the log?
You do — it lives on your accounts, in plain language.