Machine identity
A dedicated machine gives the agent a concrete operating identity: known device, network context, local runtime, stored credentials, and controllable environment.
Secure operators, not loose chatbots
Agents should operate like controlled users of the system: dedicated machine identity, authenticated API calls, bounded permissions, visible actions, and reviewable logs.


A dedicated machine gives the agent a concrete operating identity: known device, network context, local runtime, stored credentials, and controllable environment.
The agent should act through approved API routes with role-bound permissions instead of unrestricted access to every system.
Agent work should appear inside dashboards, queues, approvals, drafts, holds, and event logs that people can inspect.
People need clear ways to pause, review, redirect, approve, revoke, or escalate agent activity.
The dashboards page shows examples of the kinds of app surfaces people and agents can share.