Reference architecture for AI agents that propose actions but cannot authorize them — immutable intent capture, an independent Decionis policy verdict (ALLOW/ESCALATE/BLOCK), verified human approval, and a SafeExecutor that consumes a single-use intent-bound grant.
typescript mcp authorization reference-architecture ai-safety human-in-the-loop ai-agents policy-as-code ai-governance agentic-ai execution-authority decionis ai-agent-permissions
-
Updated
Aug 31, 2026 - TypeScript