Skip to content
optaimiOptaimi home

Note /

When an agent acts on its own

The question sounds like it is about the agent, and nothing about the agent answers it. What waits for a person is decided by the action, and it was settled before your agents went to work.

Under the default posture, it waits

Every deployment ships with a hardened default, and under that default an action with consequences waits for human sign-off. An agent can draft the message or stage the change; a person approves it before it goes anywhere. The gate is what a deployment starts with, rather than something added to an open system after someone gets nervous. That is the substance of what hardened means, and this note is about the part that sentence leaves out: what counts as an action with consequences, and who decided.

The test is the consequence, not the agent

An agent is not autonomous or supervised as a whole. The gate tracks what the action does, so the same agent can complete one task on its own and stop on the task beside it, because the two differ in what they change rather than in who is carrying them out. Asking whether your agent is allowed to act by itself is therefore the wrong shape of question. The answer is a list of actions, not a setting on an agent.

Two limits, and the quieter one comes first

The approval gate is the second limit rather than the first. Least privilege comes before it: an agent gets the tools its job needs and nothing else, so an agent that chases invoices can read your accounting system and was never handed anything to pay with. A whole class of actions is therefore never on the table to approve or refuse, and reading only the second limit makes the posture look thinner than it is.

Nobody asks the agent

Which actions wait is set when the deployment is configured. The agent does not weigh up its own action in the moment and decide it feels confident enough to proceed, because a model’s confidence is not evidence, and a gate the agent can talk its own way through is not doing the job you wanted a gate for. The line is a property of the deployment, which is also why it can be stated to you in advance rather than described in general terms.

What the agent did afterwards is a different question with a different answer. An agent activity audit trail is a priced item on the add-on menu rather than something an install includes by default.

You chose it, and it is written down

The default arrives with the line already drawn, so nobody has to design a posture from nothing. Where your deployment sits is yours to settle during the install, and it is recorded in the handover document you sign rather than left in a configuration file nobody reads again. There is a floor under all of it: a dangerous-equivalent posture with the guardrails off is refused outright, at any price, so the choice is genuine but it is not unlimited.

What this note does not settle

Who is accountable when an action goes wrong is a separate question and this is not the answer to it. What is published is narrower: after handover you are responsible for how the agents are used, and our obligation is hardening to the agreed posture plus the training and guidance that come with every install. Where legal responsibility lands is set by the agreement you sign, not by a note on a website.

All notes