Context card
Control points for AI agents
Who controls what an AI agent is allowed to do?
The short answer
Not the model. What an AI agent may do is decided by the systems around it: its own identity, the permissions granted to that identity, a gateway that checks every tool call, logs that record each action and human approvals for consequential steps. Documentation has to describe these control points, not only the agent.
For: Technical writers, project managers and developers introducing AI agents
Key points
- Give each agent its own identity, separate from the user it works for.
- Grant the fewest permissions needed, for no longer than needed.
- Route tool calls through a gateway that authenticates, authorizes and logs them.
- Keep a traceable record of who triggered which action with which result.
- Define where a person must approve before an action takes effect.
The context
From answers to actions
An AI agent plans several steps and calls tools — APIs, databases, protocols such as the Model Context Protocol. Once it can change data or systems, the question is no longer how good the answer is but what the agent is permitted to do.
The control points
- Identity: the agent acts under an identity of its own, so every action can be attributed and revoked.
- Permissions: role-based access control and the principle of least privilege limit which tools and data the identity can reach.
- Gateway: a central point checks each tool call against policies before it reaches the target system.
- Evidence: logging and an audit trail record the user, the agent, the tool, the decision and the result.
- Human approval: human in the loop steps for actions with consequences.
What it means for documentation
Describe per agent: purpose, identity, permitted tools and data, approval points, logging, how access is revoked and who is accountable. These records do not show compliance with any regulation by themselves; they make the agent's scope checkable.
Questions readers ask next
- Is a system prompt enough to restrict an agent?
- No. Instructions in a prompt can be ignored or bypassed; permissions and gateway policies are enforced outside the model.
- Why a separate identity for the agent?
- So its actions can be told apart from the user’s, limited on their own and revoked without locking out the user.
Sources
- Model Context Protocol specification — Model Context Protocol
- Least privilege — NIST Computer Security Resource Center
Review log and changes
Every context card is checked against its sources before it is published, and again whenever it changes; the date under the byline is the last review. Corrections (something was wrong) and additions (something was missing) are logged below with date and time (Berlin time). Typos, formatting and link fixes are not listed.
Reviewed
No corrections or additions since publication.