Loading

Controlling What Agents May Do

Delegated work is work you did not directly supervise, so the controls matter more than they would for an ordinary integration.

Where to find it

The allowlist, the advertised skills and the task history are held in the A2A datastores, opened from All Datastores. There is no dedicated panel section for A2A.

The allowlist

Only allowlisted agents may delegate to you, and you may only delegate to allowlisted agents. Keep both lists short and reviewed — an entry added for a trial that ended is exactly the kind of thing that persists.

Narrow skills

Advertise the skills you actually want used. A broadly defined skill invites a calling agent to attempt things you did not intend, and the agent has no way of knowing you did not intend them.

A person in the loop

For anything with real consequence — money, messages to real people, disposal, anything statutory — have the task produce a proposal a person approves rather than completing autonomously. The approvals mechanism already exists and is the natural fit.

Failure is normal

Tasks fail, stall and get abandoned. Decide what happens to a task that has been in progress for a day with no update, and make sure it surfaces somewhere a person looks rather than sitting in a state nobody monitors.

Log everything and read it

Task history is your only account of what an external agent asked for and what was done. Review it regularly at first. The useful signal is not errors but surprises — tasks doing something reasonable that you did not anticipate anyone asking for.

Treat instructions as untrusted

An instruction arriving from another agent is input, not authority. It should be able to ask for work within the skills you advertised, and nothing beyond — no matter how the request is phrased.