Agent runtime
Planning, model calls, memory, and retries
Requests a tool action with an actor and target.
Execution path
The agent runtime plans the action. Identity sets standing access. Deixic checks workspace policy before the tool call and gets approval for sensitive changes.
System boundary
Deixic
Allow this agent action?Execution path
Each system retains authority over its own data. Deixic owns the policy and approval state for the action it receives.
Planning, model calls, memory, and retries
Requests a tool action with an actor and target.
Standing access and credential scope
Supplies the identity and credential reference used for the request.
Workspace policy, approval state, and action history
Allows, denies, or pauses the action before execution.
Business data and the resulting side effect
Executes an accepted call and returns the result.
Security findings, controls, audits, and compliance evidence
Remain authoritative for their own findings and control status.
Start point
Start with one production action that lacks a defined approval path.
See the product · Browse supported connectors · Request a demo