30 April 2025 / Applied AI / 8 chapters

Keep permission decisions visible during the run

From Deciding what a tool-using agent can read and change

The user needs to know when the agent is reading, proposing or changing. A single animated status indicator hides too much. Show the current task, source being accessed, requested tool, approval state and latest confirmed result in ordinary language.

Tool calls should carry a task ID, actor, workload identity, policy decision and correlation ID. The resulting event record can include argument classifications and object references while redacting credentials and unnecessary content. Store both allowed and denied calls. A denied request may reveal a tool-selection problem, a prompt-injection attempt or an incorrectly narrow policy.

Set limits for one run: maximum records read, external calls, elapsed time, cost and proposed actions. When a limit is reached, stop with an explicit reason. Automatically opening a larger scope because the task is incomplete turns an operational limit into a suggestion.

Cancellation needs to stop new calls and identify work already in flight. An external request may complete after the user presses stop, so the interface should distinguish cancellation requested, agent stopped and all side effects reconciled.

Permission changes should be versioned. Each task record can point to the tool registry version and policy version used. When a later review finds unexpected access, the team can reconstruct the actual rules instead of assuming the current configuration also governed the earlier run.

Alerts should focus on meaningful events: denied attempts to reach restricted sources, unusual read volume, repeated approval failures, calls outside the normal task sequence and uncertain write outcomes. Without a review path, the records accumulate without changing how the workflow is operated.

All articles