01 · Mental model
Agency has three independent dimensions
Functionality asks which operations the system exposes. Permission asks what resources and scopes those operations can reach. Autonomy asks whether an action happens automatically, after confirmation, or only as a recommendation.
Teams often reduce one dimension and assume risk is controlled. A read-only function can still expose sensitive data; a narrow action with tenant-wide permission can still create large impact; a safe tool can become dangerous when invoked repeatedly without a budget or approval gate.
02 · Visual explanation
03 · Compare and decide
Bound each dimension explicitly
| Decision lens | Risky default | Governed design |
|---|---|---|
| Function | Generic shell or unrestricted API | Narrow business verbs |
| Permission | Shared admin credential | Per-run, least-privilege identity |
| Autonomy | Execute whenever the model asks | Recommend, simulate, approve, execute |
| Scope | Tenant-wide and unbounded | Resource, time, row, and cost limits |
04 · Cybersecurity example
Containment recommendation agent
An agent analyzes compromised identities and proposes containment actions.
Read-only tools collect scoped evidence.
The model proposes one containment plan.
Policy checks identity, asset criticality, and change window.
A human approves before a separate executor acts.
Outcome: The reasoning capability is useful without granting the model standing administrative authority.
05 · What to remember
The 60-second recall
Least privilege applies to tools, identity, data, and time.
Recommendation and execution should be separate for high-impact actions.
Budgets constrain cumulative harm, not only cost.
Teach-back prompt: Explain this concept to a teammate using the diagram, then name one failure mode and the control that stops it.
06 · Questions people ask
FAQ
07 · Primary sources