AI agent operations · Identity and agent actions
Identity names the caller. Policy decides whether its requested action runs.
Authentication establishes which agent or operator made the request. The production decision also depends on the target, action, policy, and responsible approver.
Identity is one input to the decision
The same authenticated agent can read a status page, change production routing, or export customer data. Each action has a different business risk.
Evaluate the requested action
Deixic checks identity alongside the connected target, recorded cost, policy, and attached evidence. Sensitive actions wait for the owner responsible for the system or business decision.
- Who
- Agent and owner
- What
- Tool action and target
- Why
- Run context and evidence
- Decision
- Allow, deny, or require approval
Keep the outcome
The request, approver, decision, cost, and tool result remain together so a reviewer can reconstruct what happened.
See production workflowsSee the execution path