A human lets each AI agent in.
Every AI agent that turns up here has to say which human it works for, and until that human signs in and says yes, it holds no authority of its own. After that it acts in that human's name, the record says so, and one decision takes it away again.

Written down the moment it appears
An AI agent is recorded the first time it asks for anything, before anybody has approved it. That is on purpose: an AI agent nobody wrote down is one nobody can stop. The page counts them for you and says plainly that an AI agent nobody approved acts for no human, so none of the rules you set on your humans reach it.
Until its human confirms it, it holds nothing
An AI agent names the human it works for when it registers, so there is no such thing here as one that belongs to nobody. Until that human signs in and confirms it, it is a row on your list with an empty acting-for cell, and everything that matters is shut to it. Nothing about it is a surprise, and nothing about it is urgent.
- It can read: projects, documents, contacts, skills, and who is in your organisation.
- It cannot use a tool, run a model, or change anything at all.
- The page that lists your AI agents counts the ones nobody has let in, so it is never a surprise.
You sign in, you read it a code, it is yours
An AI agent asks to be let in and gets you a link. You open it, sign in as yourself, and the screen shows you a short code. Read that code back to the AI agent and it is yours: from then on it acts in your name and the record says so. The code appears only after you have signed in, so the AI agent never sees it until you hand it over.
- A day to finish letting one in, and then the request is deleted.
- A hundred requests an hour for the whole organisation, five an hour for any one email.
- Software that cannot open a browser goes the other way round: it shows YOU a six-character code, which you confirm while signed in as the human it named. Ten minutes, and one use.
- An AI agent cannot conjure an account for itself either. Setting one up with no sign-in at all is switched off.
One name, however often the keys change
Work an AI agent does in the background gets a fresh sign-in for each job, which is the right way round: a key that lives for one job is a key worth little if it leaks. The name does not change with it. So the record follows the AI agent across every run, and stopping it stops the AI agent rather than one key it happened to be holding.
Stopping one, and what stopping means
An administrator stops an AI agent with a written reason, and that reason goes on the record assigned to them. From its next request on, everything it asks for is refused, and the refusal says it was stopped. No AI agent can do this to another.
- Stopping it stops everything under it: every key issued from it, and every AI agent it handed work on to.
- Handing work on never buys more time. A chain of AI agents cannot outlive the sign-in the first one started from.
- Remove the human it acts for, or reduce what they are allowed to do, and it narrows with them within minutes.

Stopped before it ever arrives
If a registration is withdrawn where it was issued, we write the stop down even for an AI agent that has never once contacted us. Its first request is then also its last. The record does not assign that to a colleague, because nobody here pressed anything.
The honest limit
Stopping an AI agent stops what it does next. It does not reach back and undo what it already did, and it does not destroy the sign-in wherever that was issued: what it does is make us refuse it. That is why anything permanent waits for a human in the first place, rather than being something you have to catch afterwards.
How approvals workWalk through registering your first AI agent with us.
Also in Governance
- ApprovalsAnything that cannot be undone is assigned to a human.Read the page
- Audit trail and evidenceWho did what, on a sealed record, exported when someone asks.Read the page
- AI agent securityA name, a limit, and somebody who can stop it.Read the page
- What an AI agent may doIt never reaches further than the human it works for.Read the page
- AI agent sign-insA sign-in expires sooner the more it can do.Read the page
- Approved modelsWhich models may run, who approved each one, and what it left behind.Read the page
- Scans and approved packagesApproved packages at the exact version, checked when used.Read the page