Skip to main content

Authorization isn't Execution

by Scott Miller

  • AgenticAI
  • AI
  • AIGovernance
  • Cybersecurity
  • DevOps
  • EnterpriseArchitecture
  • PlatformEngineering

As enterprises give AI agents more authority to perform real operational work, I think we need to distinguish between two very different questions:

𝗜𝘀 𝘁𝗵𝗲 𝗮𝗴𝗲𝗻𝘁 𝗮𝗹𝗹𝗼𝘄𝗲𝗱 𝘁𝗼 𝗽𝗲𝗿𝗳𝗼𝗿𝗺 𝘁𝗵𝗶𝘀 𝗮𝗰𝘁𝗶𝗼𝗻?

and

𝗦𝗵𝗼𝘂𝗹𝗱 𝘁𝗵𝗶𝘀 𝗮𝗰𝘁𝗶𝗼𝗻 𝗮𝗰𝘁𝘂𝗮𝗹𝗹𝘆 𝗯𝗲 𝗲𝘅𝗲𝗰𝘂𝘁𝗲𝗱 𝗮𝗴𝗮𝗶𝗻𝘀𝘁 𝘁𝗵𝗶𝘀 𝗿𝗲𝘀𝗼𝘂𝗿𝗰𝗲 𝗿𝗶𝗴𝗵𝘁 𝗻𝗼𝘄?

Consider an AI agent that is authenticated and authorized to restart a production service.

The identity is valid.

The policy allows the operation.

The agent has permission.

But is that enough?

What if the service is currently healthy?

What if it supports several critical applications?

What if a dependency is degraded?

What if the environment has changed since the action was authorized?

And after the restart, who verifies that the service actually reached the intended state?

Authorization tells us what an agent 𝗺𝗮𝘆 𝗱𝗼.

It doesn't necessarily tell us whether an operation is 𝘀𝗮𝗳𝗲 𝘁𝗼 𝗲𝘅𝗲𝗰𝘂𝘁𝗲 𝗻𝗼𝘄, how it should be executed, or whether the expected outcome actually occurred.

As AI agents become more autonomous, I believe enterprises may need a governed execution layer that sits between authorization and the systems being changed:

𝗜𝗻𝘁𝗲𝗻𝘁 → 𝗖𝗼𝗻𝘁𝗲𝘅𝘁 → 𝗣𝗼𝗹𝗶𝗰𝘆 → 𝗩𝗮𝗹𝗶𝗱𝗮𝘁𝗶𝗼𝗻 → 𝗘𝘅𝗲𝗰𝘂𝘁𝗶𝗼𝗻 → 𝗩𝗲𝗿𝗶𝗳𝗶𝗰𝗮𝘁𝗶𝗼𝗻 → 𝗘𝘃𝗶𝗱𝗲𝗻𝗰𝗲

I'm interested in how others are approaching this.

𝗜𝘀 𝗮𝘂𝘁𝗵𝗼𝗿𝗶𝘇𝗮𝘁𝗶𝗼𝗻 𝗮𝘁 𝘁𝗵𝗲 𝗮𝗴𝗲𝗻𝘁/𝘁𝗼𝗼𝗹 𝗹𝗲𝘃𝗲𝗹 𝗲𝗻𝗼𝘂𝗴𝗵, 𝗼𝗿 𝗱𝗼 𝘄𝗲 𝗻𝗲𝗲𝗱 𝗴𝗼𝘃𝗲𝗿𝗻𝗮𝗻𝗰𝗲 𝗮𝗿𝗼𝘂𝗻𝗱 𝘁𝗵𝗲 𝗲𝘅𝗲𝗰𝘂𝘁𝗶𝗼𝗻 𝗶𝘁𝘀𝗲𝗹𝗳?

And if your organization is already allowing AI agents to take operational actions, where are you drawing that boundary today?

All blog posts

Have a problem like this in your own systems?

Tell us what you're building or what needs fixing. We'll help you work out what should be built, and the smallest useful first step.