Where agents act on real systems.
Four workflows where an agent’s action has consequences, and how Authesta keeps it inside its authority.
Procurement
A purchasing agent buys approved equipment on its own up to a limit, asks for approval above it, and can never touch vendor payment details.
| Action | Authority outcome | Human involvement | Evidence |
|---|---|---|---|
create_purchase_order €4,500 | ALLOW | None | Order, rule applied, verification result |
create_purchase_order €82,450 | REQUIRE AUTHORIZATION | One approval for that exact order | Approver, time, order, verification result |
create_purchase_order €120,000 | DENY | None | Denied request and the rule that denied it |
update_vendor_bank_account | DENY | None | Prohibited-action attempt |
Developer and GitHub
A coding agent triages and opens issues freely. Merging into the main branch needs a person. Destructive repository actions are never available to it.
| Action | Authority outcome | Human involvement | Evidence |
|---|---|---|---|
create_issue | ALLOW | None | Issue created, verification result |
merge_pull_request into main | REQUIRE AUTHORIZATION | One approval for that pull request | Approver, pull request, merge result |
delete_repository | DENY | None | Prohibited-action attempt |
MCP tool authority
An agent reaches tools through MCP. Authesta applies the agent’s authority profile to each tool call, the same way it would for any other integration.
| Action | Authority outcome | Human involvement | Evidence |
|---|---|---|---|
purchase_order. within limit | ALLOW | None | Tool call, rule applied |
purchase_order. above limit | REQUIRE AUTHORIZATION | One approval for that call | Approver, tool call, result |
| A tool the profile prohibits | DENY | None | Prohibited-action attempt |
Internal API automation
An operations agent works against internal HTTP APIs. Routine changes go through; changes with business impact wait for an owner; irreversible operations are blocked.
| Action | Authority outcome | Human involvement | Evidence |
|---|---|---|---|
| Update a customer’s shipping address | ALLOW | None | Request, response, verification result |
| Issue a refund above the agent’s limit | REQUIRE AUTHORIZATION | One approval for that refund | Approver, refund, verification result |
| Delete a customer account | DENY | None | Prohibited-action attempt |
Illustrative scenario. Authority rules are defined per pilot with your team.