← Agents
Cost Sentinel
Cost Sentinel · owned by Platform Team
Active
Autonomy
The trust dial. It decides whether an in-scope, guardrail-clean action runs on its own — not whether the agent may act outside its grants.
Acts on its own — within scope + guardrails
Scope
Least privilege: the agent can touch only what is explicitly granted.
| Read | Sync | Flush | Restart | Roll back | Rotate | Invoke | |
|---|---|---|---|---|---|---|---|
| Service | |||||||
| Integration | |||||||
| Deployment | |||||||
| Data store |
Default deny — access exists only where explicitly granted. Toggle a cell to grant or revoke.
Guardrails
Per-action safety rules on top of scope. Most-restrictive-wins — a guardrail can force approval even for an autonomous agent.
Production needs approval
Any action on a production target drops to the approval queue.
Rollback needs approval
Rollbacks always require a human sign-off.
Blast-radius cap
Limit how many resources one action may touch.
Max resources
Rate limit
Cap actions per rolling hour.
Max actions / hour
Ownership
An agent is bound to a valid owner. If that authority disappears, the agent auto-pauses on its next action — no zombie agents acting on a ghost's authority.
Owner: Platform Team (team)