7.2 Agent workflow
A typical controlled workflow:- Interpret: convert the user’s request into a concrete objective.
- Plan: identify steps, required tools, assumptions, and risks.
- Authorize: check permissions and whether confirmation is required.
- Execute: perform a small, scoped operation.
- Verify: inspect the result, run checks, or query the relevant system.
- Report: summarize what happened, what failed, and what remains.
- Stop: end the task when complete, when blocked, or when a safety condition is triggered.
7.3 Permission tiers
A useful permission model can distinguish between:- Read-only: inspect approved resources without changing them.
- Draft: prepare proposed changes without committing them.
- Reversible action: perform changes that can be reliably undone.
- Sensitive action: require explicit confirmation before sending, publishing, purchasing, deleting, or changing access.
- Prohibited action: disallow operations that violate policy, exceed authority, or create unacceptable risk.