Reference
One question, answered in full, for the people who have to sign off on an agent.
- posts
- 27
- updated
- feed
- rss

Least privilege for AI agents: how to scope what an agent can touch
Most agents run on a borrowed login with far more access than the job needs. Scope them by action, not by system, and enforce it outside the model.

Microsoft Copilot Studio approvals: what the human review actions do, and where they stop
A fair reading of Copilot Studio's Request for information action and multistage approvals, from Microsoft's docs: what they pause, who they ask, and what they leave to you.

Model Context Protocol for operations teams: what to ask before you connect a server
MCP is the standard way agents plug into tools and data. A server can read your systems and act in them. What the spec itself says about consent and safety, and what to check before connecting one.

n8n human in the loop: Wait nodes, tool approval, and the who-clicked problem
n8n's three ways to put a person in front of an agent's action, read from its docs, and the difference between a link anyone can click and a verified approver.

Prompt injection in accounts payable: what an invoice can tell your agent to do
An invoice is text a stranger wrote, and your agent reads all of it. Prompt injection turns that text into instructions. You can't filter it out. You can limit what it can do.

Retries, idempotency and side effects: why a retried agent pays twice
An agent that retries 'pay invoice' after a timeout can pay it twice. What idempotency means, why agents make it worse, and what to check before an agent gets write access.

Segregation of duties for AI agents: when one agent initiates and approves
Segregation of duties says no one person should initiate, approve and record the same transaction. An agent that does all three breaks the rule. How to map SoD onto agents.

What is shadow mode for AI agents?
Shadow mode runs the agent on live work while your people still do the job. The agent decides, nothing happens, and you compare. It is the cheapest go-live test there is.

SOC 2 when the product is an agent: what the report covers, and what it does not
A SOC 2 report tells you a vendor's controls over your data were designed and, in Type 2, operated. It does not tell you what their agent will do on your work. How to read one.

The stack for governed agents: six layers between a model and your ledger
A map of what sits between a language model and the system it changes: model, orchestration, tools, control, record, and the system of record itself.

The two-person rule for AI agents: overrides, dual authorisation, and Meta's Rule of Two
Two people to override a block. Where the rule comes from, what it should cover for an agent, and why Meta's 'Agents Rule of Two' is a different rule with a confusing name.

What is an agent approval policy?
An approval policy decides which agent actions go ahead, which wait for a person, and which never happen. Most teams have a paragraph. You need a table.