AI agents you name, limit and stop.
Most trouble with AI agents starts the same way: a key gets pasted into a script, and after that nobody can say which machine did what, or on whose say-so. Give each AI agent a name of its own and those questions have answers: who it works for, what it may touch today, and how to stop it, which takes effect on its very next request.

A name of its own, not a borrowed key
Give an AI agent an identity of its own and it stops signing in as a human. It is written down the first time it appears and keeps that one name however often its keys are replaced. Every sign-in is placed in exactly one organisation before anything else is read, so one customer's settings can never be reached while deciding about another's.
How an AI agent gets a nameIt can never do more than its human
What an AI agent may do is the overlap between two lists: what somebody approved it to do, and what that human is allowed to do at this moment. The second list is looked up again, not remembered from when the AI agent was set up. Take somebody's access away and their AI agents lose it with them, without anybody having to remember a second job.
What an AI agent may do
Anything permanent stops and waits
Deploying, publishing, merging, sending something to a customer and changing how data is stored are permanent wherever they run. An AI agent that asks for one of those gets a reference number instead of a result, and a human decides.
How approvals workAssigned to both, on the same line
When an AI agent acts, the line is assigned to both: the machine that did it, and the human whose authority it was using. Not the machine twice. Every tool it reaches is written down with what it asked for, what came back, and how long it took, and a call that was refused is written down as a refusal rather than as a quiet nothing.
What the record holdsA sign-in that ends on its own
A sign-in for a human's terminal expires sooner the more it can do: seven days for full access, thirty for running a project, ninety for read-only. A sign-in for a machine has a length you choose, and can be held to particular countries or networks on top of your organisation's own rules.
How sign-ins are limitedRevoking works on the next request
Stop an AI agent and the next thing it asks for is refused, with a message saying it was stopped rather than that it was mistyped. Being honest about the limit: this stops what comes next. It does not undo what the AI agent already did, and no product can. That is why the permanent actions wait for a human in the first place.

Ask us what governing your first AI agent would take.
Also in Governance
- ApprovalsAnything that cannot be undone is assigned to a human.Read the page
- Audit trail and evidenceWho did what, on a sealed record, exported when someone asks.Read the page
- AI agent identityA human lets an AI agent in, and can stop it again.Read the page
- What an AI agent may doIt never reaches further than the human it works for.Read the page
- AI agent sign-insA sign-in expires sooner the more it can do.Read the page
- Approved modelsWhich models may run, who approved each one, and what it left behind.Read the page
- Scans and approved packagesApproved packages at the exact version, checked when used.Read the page