The agent is not the product. The control over it is. This console shows the three mechanisms that make an AI agent safe to put in front of guests — and they are the same three for every agent you add after it.
Every exception is measured against governance written in plain Markdown, not code. Inside the Ambassador's ceiling and all conditions met, the agent acts. Over the ceiling, or a condition it cannot evidence, it stops and asks — the Ambassador for front-desk calls, the Manager on Duty for anything carrying revenue or policy risk. The agent never decides what it is allowed to decide.
When a decision proves itself, the Manager on Duty can baseline it: approve that one kind of task, scoped to exact bounds, and the agent handles it automatically from then on. Revocable at any time. This is the single control point for the whole estate — the same gate governs this agent, the next agent, and every new capability either of them gains. Automation is something a manager grants, never something a deployment assumes.
Each decision — autonomous or human — is sealed into a tamper-evident Witness chain: what was decided, which clause governed it, who decided, and when. Append-only and externally anchored, so it cannot be quietly revised afterwards. The EU AI Act Article 12 record is a by-product of operating, not a project you start once a regulator asks.
Loading…