Article chapter 07 of 08
Show permission decisions while the agent runs
The user needs to be able to tell whether the agent is reading, proposing or changing something. One animated "working" indicator hides too much. I'd show the current task, the source being accessed, the tool being requested, the approval state and the latest confirmed result in plain language.
Each tool call should carry a task ID, actor, workload identity, policy decision and correlation ID. The event record can include argument classifications and object references, with credentials and unnecessary content redacted. Store denied calls as well as allowed ones. A denied request might point to a tool-selection problem, a prompt-injection attempt or a policy that's too narrow.
Set limits for a single run: maximum records read, external calls, elapsed time, cost and proposed actions. When the agent hits a limit, it should stop and say why. It shouldn't automatically widen its own scope because the task isn't finished yet.
Cancellation has to stop new calls and identify work that's already in flight. An external request might complete after the user presses stop, so the interface should tell apart "cancellation requested", "agent stopped" and "all side effects reconciled".
Version your permission changes. Each task record can point to the tool registry version and policy version it ran under, so when a later review finds unexpected access, the team can rebuild the rules that applied at the time instead of assuming today's configuration was in place for that earlier run.
For alerts, I'd focus on events that mean something: denied attempts to reach restricted sources, unusual read volume, repeated approval failures, calls outside the normal task sequence and write outcomes nobody can confirm. Someone also has to actually review them, or the records just pile up and nothing about how the workflow runs changes.