Skip to content

Runtime control and live approvals

Agent Runtime Control is the operational view of agent status, pending decisions and governed execution. It does not replace Gateway enforcement. Use it to observe, approve where authorised, and contain operation.

  • Agent identity and owners are current.
  • Risk tier and ATF readiness support the intended autonomy.
  • Required connectors are healthy and least-privileged.
  • Tool Permissions and Runtime Access Policies are exact and active.
  • Approval, logging, monitoring and expiry requirements are configured.
  • Simulation and failure-path testing are complete.

Inspect the complete action context: agent, purpose, requested action, target, resource, data class, environment, risk, policy version, expiry and expected effect. Approve only when the request matches the authorised business purpose and remains necessary at decision time.

Approval is not execution. Immediately before action, Gateway revalidates policy, approval, connection, identity and request context. Changed, stale, replayed, expired or already-consumed authority is rejected.

Suspend an agent or revoke policy when identity, purpose, owner, connection, evidence or control assumptions are no longer trustworthy. Use the narrowest control that safely contains the issue, but do not delay a broader stop when impact is uncertain.

Record reason, decision owner, affected work, communications and recovery conditions. Test that pending and retried requests cannot continue under revoked authority.

Review denials, unusual request volume, repeated approval prompts, policy mismatches, connector failures, timeouts and evidence gaps. A high denial rate may show malicious behaviour, poor agent planning or an incorrectly designed policy; investigate rather than automatically widening access.