An owner, a job, no keys, and an off switch.
Updated August 2026
A firm that would not let a script near client mail will hand the same work to a junior, because a junior has a boss, a job description and limits. Agents run the same way. Nothing installs on anyone's computer.
| The rule | What it means |
|---|---|
| An owner | One named person answers for it. |
| A job | One written job it cannot leave: which kinds of work, on which engagements. |
| No keys | No passwords of its own, and it never sees raw client data. |
| Set at registration | The bound |
|---|---|
| Purposes | The kinds of work it may run. A request outside them stops before anything is read. |
| Systems | Which connected systems answer it. An organizer chase needs Karbon, Outlook, and SharePoint, so that is all it gets. |
| Engagements | The clients and engagements its job covers, and no others. |
| Spend of attention | How much it may run. A spent budget stops the agent, and it says so rather than running quietly past it. |
| Consequence line | Which effects need a person. A draft passes on its own; a send waits, unless the firm has expressly delegated that exact kind of action. |
The same registration whether the firm bought the agent, built it, or put one of its own workflows on a schedule.
| The question | What the record holds |
|---|---|
| Who ran | The agent, its owner, and the job it ran under. |
| What it read | The sources consulted, engagement by engagement. |
| What left the firm | What was released to the model, under which policy. Stand-ins and approved facts, never client names or figures. |
| What it did | Each action taken, and what the system of record confirmed back. |
The record each run leaves lives in the console.
Every agent, its owner and its current authority sit under People in the console, which is also where one is withdrawn. The same ground from an employee's chair: Working with an agent.