Governance
Authority and intent are different questions
Whether an agent is allowed to do something and whether anyone wanted it done are two separate checks. Most approval designs blur them, and that is where the surprises come from.
An agent with access to the billing system issues a refund. It had permission. The customer had asked for one. Nothing was technically wrong - and the finance lead is still unhappy, because policy says a refund that size goes to a manager first.
Now the opposite. A manager tells an agent, in so many words, to delete a set of records it has no rights over. Somebody clearly wanted it done. It still should not happen.
Those are two different failures, and they point at two different questions.
Allowed is not the same as wanted
Authority is the question of whether this agent, acting as this identity, may perform this action at all. It is about permissions, and the answer does not depend on the conversation.
Intent is the question of whether a person actually wants this particular action, on this particular thing, right now. It is about the moment, and no permission system can answer it.
Blur the two and you get one of two bad designs. Either every permitted action goes ahead, and people find out what the agent decided after the fact. Or every action asks for confirmation, people learn to click yes without reading, and the confirmation stops meaning anything.
Two questions, two owners
In Yekar.AI the two are kept apart, and each has its own owner. Authority belongs to whoever is responsible for the system being touched - they decide what an agent may do there, and which actions are gated. Intent belongs to the person the work is for - they confirm that this specific action is the one they meant.
One approval policy applies across an organisation's agents, so the answer to "what needs sign-off here?" does not change depending on who built the agent or how carefully they wrote its instructions.
Permission tells you an agent can. It has never told anyone that it should.
What the record should say
The distinction pays off afterwards. When something is questioned, "the agent was allowed" and "someone approved it" are different defences, and a record that mixes them cannot offer either cleanly. Kept apart, the record shows which identity the action ran under, which rule gated it, who confirmed it, and when.
Getting the gates right
- Gate by consequence, not by tool. Reading a customer record and deleting one may go through the same integration. They are not the same risk.
- Ask the person who can judge. An approval sent to someone without the context is a rubber stamp with a delay.
- Keep the list short. Every gate you add makes the others easier to ignore.
An agent people trust is not one that asks about everything. It is one that asks about the right things - and keeps "could it?" and "did anyone want it to?" as two separate answers.