04 / Field note · 01

Capability, not custody.

An agent becomes useful when it can act. It becomes dangerous when acting requires us to hand it the identity, credentials and durable authority of the operator.

The false choice

Most agent integrations offer two unsatisfying modes: a model that can only suggest, or a model wrapped around credentials powerful enough to operate an entire account. That is not autonomy. It is authority without a boundary.

A capability is a contract

A useful capability says what operation is available, over which resources, under which policy, for how long and with what evidence. The agent can request it without possessing the underlying credential or inventing a new path to the system.

Execution is a lifecycle

Intent becomes a typed request. Policy determines whether it is admissible. Planning freezes the proposed effects. Approval authorizes the plan rather than an open-ended session. Execution is followed by observation, verification and a durable audit record.

The larger consequence

When capability is separated from custody, agents can become more powerful without making trust binary. That is the architectural condition for genuine multi-agent teams: authority can be composed, reviewed and revoked.

The future is not agents with all our passwords. It is systems capable of granting narrow authority with public reasons.