Where agents act on real systems.

Four workflows where an agent’s action has consequences, and how Authesta keeps it inside its authority.

Procurement

A purchasing agent buys approved equipment on its own up to a limit, asks for approval above it, and can never touch vendor payment details.

Procurement agent
ActionAuthority outcomeHuman involvementEvidence
create_purchase_order €4,500ALLOWNoneOrder, rule applied, verification result
create_purchase_order €82,450REQUIRE AUTHORIZATIONOne approval for that exact orderApprover, time, order, verification result
create_purchase_order €120,000DENYNoneDenied request and the rule that denied it
update_vendor_bank_accountDENYNoneProhibited-action attempt

Developer and GitHub

A coding agent triages and opens issues freely. Merging into the main branch needs a person. Destructive repository actions are never available to it.

Software delivery agent
ActionAuthority outcomeHuman involvementEvidence
create_issueALLOWNoneIssue created, verification result
merge_pull_request into mainREQUIRE AUTHORIZATIONOne approval for that pull requestApprover, pull request, merge result
delete_repositoryDENYNoneProhibited-action attempt

MCP tool authority

An agent reaches tools through MCP. Authesta applies the agent’s authority profile to each tool call, the same way it would for any other integration.

Agent using MCP tools
ActionAuthority outcomeHuman involvementEvidence
purchase_order.create_purchase_order within limitALLOWNoneTool call, rule applied
purchase_order.create_purchase_order above limitREQUIRE AUTHORIZATIONOne approval for that callApprover, tool call, result
A tool the profile prohibitsDENYNoneProhibited-action attempt

Internal API automation

An operations agent works against internal HTTP APIs. Routine changes go through; changes with business impact wait for an owner; irreversible operations are blocked.

Operations agent on internal APIs
ActionAuthority outcomeHuman involvementEvidence
Update a customer’s shipping addressALLOWNoneRequest, response, verification result
Issue a refund above the agent’s limitREQUIRE AUTHORIZATIONOne approval for that refundApprover, refund, verification result
Delete a customer accountDENYNoneProhibited-action attempt

Illustrative scenario. Authority rules are defined per pilot with your team.

Bring one of these workflows to a pilot.