Agent guide
Agents that touch multi-party shared state need a short contract: what they may do, when to stop, and who concludes writes. This page is that contract at the Legate interface.
Authority detail: Access model. Forward path: Write path. Maturity: Integration Surfaces.
Safe tasks
| Task | Pack | Notes |
|---|---|---|
| Observe scoped shared state | legate.read | Prefer read before any prepare |
| Dry-run a change | legate.write + consent | simulate only. No commit |
| Build a proposal for review | legate.write + consent | prepare returns a review payload. Still no commit |
| Submit an already-signed payload | legate.write + consent | Only after an external signer has signed |
Recommended path
- Confirm the surface is Live or entitled by arrangement.
- Connect with a short-lived credential. See Connect.
- Read the shared record before proposing a write.
- Simulate, then prepare. Hand the proposal to a human or dedicated signer.
- Submit only the signed payload. Do not invent a signature in the model host.
- On denial or not-ready, stop and follow Exception paths.
Stop conditions
Stop and escalate to an operator when:
- Credential is missing, expired, or wrong audience
- Pack or write consent is insufficient (
403) /readyfails or the peer path is unavailable- Prepare returns a shape the human reviewer rejects
- The task asks for judgment, scoring, or policy source this portal does not publish
Must not
- Leave lasting commit power in the agent host or MCP process
- Treat prepare as commit
- Escalate read credentials by renaming write tools
- Paste production tokens, tenant hostnames, or live Agent Cards into tickets or docs
- Claim Arbiter seal or assessor readiness unless Integration Surfaces labels that surface for your environment