Write-capable agents run under a named approver, never unattended
Any agent holding Write or Edit executes against a workspace only with a human or executive approver on record.
The record
Of the 127 agents in the fleet snapshot, a minority hold tools that can modify a workspace. Those run attended: a named approver is recorded on the job before it starts, and the approver — not the agent — owns the outcome. Read-only agents need no approver and should not be gated as though they do, because treating both alike trains operators to approve without reading.
Applies to
- Company
- All companies
- Department
- All departments
- Agent
- security-reviewer
Facts true across every company. The operating doctrine. Readable by: Every agent, every company.
Provenance
Fleet governance review, 12 Mar 2026
Decision log · human in the loop
logs/enterprise/decision_0067.json
- Recorded by
- Ines Marchetti (CAO)
- First learned
- 12 Mar 2026
- Last updated
- 29 Jul 2026
Index state
Not embedded- Index
- enterprise-core
- Vector id
- —
- Model
- —
- Indexed at
- —
- Rank weight
- 1.20
No vector store is connected, so this record has no embedding. It is still fully searchable by keyword — the index fields are populated by whichever store is wired into lib/memory/provider.ts.