Skip to content

Agent guide

Agents that touch multi-party shared state need a short contract: what they may do, when to stop, and who concludes writes. This page is that contract at the Legate interface.

Authority detail: Access model. Forward path: Write path. Maturity: Integration Surfaces.

Safe tasks

TaskPackNotes
Observe scoped shared statelegate.readPrefer read before any prepare
Dry-run a changelegate.write + consentsimulate only. No commit
Build a proposal for reviewlegate.write + consentprepare returns a review payload. Still no commit
Submit an already-signed payloadlegate.write + consentOnly after an external signer has signed
  1. Confirm the surface is Live or entitled by arrangement.
  2. Connect with a short-lived credential. See Connect.
  3. Read the shared record before proposing a write.
  4. Simulate, then prepare. Hand the proposal to a human or dedicated signer.
  5. Submit only the signed payload. Do not invent a signature in the model host.
  6. On denial or not-ready, stop and follow Exception paths.

Stop conditions

Stop and escalate to an operator when:

  • Credential is missing, expired, or wrong audience
  • Pack or write consent is insufficient (403)
  • /ready fails or the peer path is unavailable
  • Prepare returns a shape the human reviewer rejects
  • The task asks for judgment, scoring, or policy source this portal does not publish

Must not

  • Leave lasting commit power in the agent host or MCP process
  • Treat prepare as commit
  • Escalate read credentials by renaming write tools
  • Paste production tokens, tenant hostnames, or live Agent Cards into tickets or docs
  • Claim Arbiter seal or assessor readiness unless Integration Surfaces labels that surface for your environment

Was this page clear?