Skip to main content
An agent is a software system that can select and use tools over multiple steps to pursue a goal. It may plan, execute a permitted operation, inspect the result, and decide what to do next. This is more powerful than a single response, but also creates more ways for a mistake to cause damage. Orbit’s agent direction should be based on bounded autonomy: agents may act only within the permissions, resources, and task scope explicitly granted to them.

7.2 Agent workflow

A typical controlled workflow:
  1. Interpret: convert the user’s request into a concrete objective.
  2. Plan: identify steps, required tools, assumptions, and risks.
  3. Authorize: check permissions and whether confirmation is required.
  4. Execute: perform a small, scoped operation.
  5. Verify: inspect the result, run checks, or query the relevant system.
  6. Report: summarize what happened, what failed, and what remains.
  7. Stop: end the task when complete, when blocked, or when a safety condition is triggered.
An agent should not keep acting simply because it has not yet found a way to declare victory.

7.3 Permission tiers

A useful permission model can distinguish between:
  • Read-only: inspect approved resources without changing them.
  • Draft: prepare proposed changes without committing them.
  • Reversible action: perform changes that can be reliably undone.
  • Sensitive action: require explicit confirmation before sending, publishing, purchasing, deleting, or changing access.
  • Prohibited action: disallow operations that violate policy, exceed authority, or create unacceptable risk.
Permissions should be enforced by the tool service, not merely described in a prompt. Model instructions are helpful, but they are not a security boundary.

7.4 Agent memory

If agents use persistent memory, it should be scoped, inspectable, and manageable. Users should be able to see what is saved, correct inaccurate information, and delete memory where supported. Sensitive information should not be retained by default simply because it appeared in a conversation.

7.5 Human oversight

The system should make it easy to pause a task, revoke a connector, cancel pending operations, and inspect action history. A pause or stop request should be handled by the orchestration and tool-execution layers, not depend entirely on the model voluntarily obeying a sentence.