TEKIMAXALOS

AI agents you name, limit and stop.

Most trouble with AI agents starts the same way: a key gets pasted into a script, and after that nobody can say which machine did what, or on whose say-so. Give each AI agent a name of its own and those questions have answers: who it works for, what it may touch today, and how to stop it, which takes effect on its very next request.

A name of its own, not a borrowed key

Give an AI agent an identity of its own and it stops signing in as a human. It is written down the first time it appears and keeps that one name however often its keys are replaced. Every sign-in is placed in exactly one organisation before anything else is read, so one customer's settings can never be reached while deciding about another's.

How an AI agent gets a name

It can never do more than its human

What an AI agent may do is the overlap between two lists: what somebody approved it to do, and what that human is allowed to do at this moment. The second list is looked up again, not remembered from when the AI agent was set up. Take somebody's access away and their AI agents lose it with them, without anybody having to remember a second job.

What an AI agent may do
A card showing an AI agent acting for Priya Natarajan: allowed to see a project, work on a project and start an AI agent, and not allowed to change your settings

Anything permanent stops and waits

Deploying, publishing, merging, sending something to a customer and changing how data is stored are permanent wherever they run. An AI agent that asks for one of those gets a reference number instead of a result, and a human decides.

How approvals work

Assigned to both, on the same line

When an AI agent acts, the line is assigned to both: the machine that did it, and the human whose authority it was using. Not the machine twice. Every tool it reaches is written down with what it asked for, what came back, and how long it took, and a call that was refused is written down as a refusal rather than as a quiet nothing.

What the record holds

A sign-in that ends on its own

A sign-in for a human's terminal expires sooner the more it can do: seven days for full access, thirty for running a project, ninety for read-only. A sign-in for a machine has a length you choose, and can be held to particular countries or networks on top of your organisation's own rules.

How sign-ins are limited

Revoking works on the next request

Stop an AI agent and the next thing it asks for is refused, with a message saying it was stopped rather than that it was mistyped. Being honest about the limit: this stops what comes next. It does not undo what the AI agent already did, and no product can. That is why the permanent actions wait for a human in the first place.

somebody at a support desk wearing a headset

Ask us what governing your first AI agent would take.

Talk to us