Should this agent action proceed?
Evaluate the actor, execution context, requested target, approval state, and deterministic policy before a governed side effect proceeds.
Agent Authority puts a governed decision boundary in front of agent actions and data release. It combines authenticated identity, bounded authority, deterministic policy, and decision-linked evidence.
No agent, runtime, or network position receives standing authority. Each governed action is evaluated against authenticated identity, request context, deterministic policy, and required evidence. An action may be permitted while its data must be narrowed, approved, or blocked for a particular destination.
Evaluate the actor, execution context, requested target, approval state, and deterministic policy before a governed side effect proceeds.
A specially governed assessor returns bounded risk evidence about a proposed action’s meaning and context. Deterministic policy decides whether that evidence requires review; the assessor cannot authorize, deny, execute, or modify the action.
Evaluate data with PII, secret, and customer-provided classifier signals in the context of the intended release.
Keep the request, policy basis, semantic assessment, decision, and resulting outcome connected for review and investigation.
Hosted workspaces and supported external integrations present actions at an enforcement boundary instead of treating a log as the control.
Evaluate an authenticated participant and specific route rather than relying on broad ambient runtime access.
Deterministic policy can allow, deny, narrow, or route a request for approval. Required enforced checks fail closed when their result cannot be obtained.
Maintain attributable evidence so teams can investigate both blocked and allowed activity.
Built-in PII and secret checks, plus customer-provided filters or classifiers, provide evidence for policy decisions at governed model, tool, channel, service, and external-agent boundaries.
Inbound model-input defenses are distinct from PII and secret egress controls; the appropriate coverage depends on the governed boundary.
Detectors and classifiers provide evidence. They do not independently publish policy or override deterministic denies.
Atellagent hosts the workspace execution surface, giving it the most direct enforcement and observation boundary.
The public client can govern documented Codex, Claude Code, and Gemini CLI hook points. It cannot claim control over lifecycle events that a host does not expose.
Read the architecture for the technical model or schedule a review of your action and data-release paths.