High-impact tools need stronger confirmation
Not every action an agent can take deserves the same level of approval.
Reading a document and transferring money should not be gated the same way. The practical approach is to tier the tools: routine things happen freely, consequential things require a person to confirm, and irreversible things require a person who has been shown enough to make a real decision. Uniform approval either blocks everything or approves everything, and in practice it approves everything.
More on AI agents
- Tool descriptions are part of the control surfaceThe label is the lever
- Agent memory can preserve poisoned contextIt stays in the water
- Agent identity should be separate from user identityTwo necks, one badge
- Delegated agents create authority chainsThe thread stays attached
- Agent loops need budgets and stopping conditionsSomething has to say enough
- Tool results are untrusted inputs tooNo sieve on the back route
