See the decision before the action becomes real.
A support agent is delegated permission to issue refunds up to $50. Change the requested amount, evaluate the semantic action, and inspect whether the credential is released.
What this page proves
1 · Requested action
financial.refund
Order #8932
2 · Runtime decision
delegated_authority_exceeded
Credential not released
In a brokered integration, the action receives the credential only after an enforceable ALLOW.
0x9e67cf21
Decision evidence includes action, delegated authority, result, reason, and ledger linkage.
Recent demo decisions
local simulationfinancial.refund · $400
0x8f7a21c4 · delegated_authority_exceeded
The action is semantic
The policy reasons about financial.refund instead of forcing teams to encode business intent in an HTTP path.
Authority can only narrow
The child agent receives a $50 refund limit even though the parent may hold broader authority.
A DENY changes execution
For brokered credentials, the denied caller does not receive the secret required to execute the action.
Want to evaluate this against a real workflow?
Private-beta pilots start with one agent, one consequential action, and a scoped rollout plan rather than a production-wide switch.