TLDRocket
Sign in

Who Gets to Define an AI Agent's Intent?

WorkOS

Who decides what an AI agent is allowed to do: the prompt or the company? Airlock splits intent from authority, so a clear task still can’t override policy.

Based on reporting by WorkOS — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

When an AI agent is asked to do work, the prompt should describe the job — not grant the permission. That’s the argument behind Airlock’s setup: the person asking defines the intent, while the organization defines what actions are allowed. The two have to work together, but they are not the same thing.

At Aaron Tainter’s Airlock demo at Agent Night on August 12, an agent asked for a token tied to its intent, then used it while working across Linear and Gmail. Airlock checked each proposed call against that declared purpose and the policies already in place. A task can explain what the agent is trying to accomplish. It cannot wave away company rules.

That matters because vague requests are a mess. “Help with billing” could mean almost anything. Airlock’s own example is much sharper: find last month’s duplicate charges and refund them. That gives the agent a time window, a goal, and the intended effect. It still leaves the agent room to search, compare, and decide how to get there. But “list charges from the last 30 days” is not the same as “issue refunds,” and the difference is not a technicality. It’s the whole point.

The same split shows up in the policy layer. In Airlock’s example, searching charges is allowed, refunds need approval, and deleting a customer record is denied because it falls outside the task. A user saying “I’m acting for the billing administrator” does not prove anything on its own. Identity has to come from the app’s controls. Authority comes from permissions and company rules, not from confident wording in a request.

The best proof is a real action. In one demo flow, an ordinary planning update to a manager went through. In another, the agent found a Linear issue about LLM token usage and wrote an email about it, but Airlock blocked the send because the message contained token-spend details that policy treated as financial data. Same tools. Different outcome. The content, the request, and the rule all mattered.

For teams building this way, the job is simple to say and annoying to do: write down who asked, what resource is involved, and what change the agent is expected to make. Then test a few proposed actions and see whether other people read them the same way. If one person thinks the assignment ends at reporting and another thinks it includes refunds, the prompt is not authorization. It’s a fuzzy note.

My take — AI-written commentary, not fact-checked reporting

This is the right split, and not just because it sounds tidy in a slide deck. Intent is what users want; authority is what systems should actually trust. Anyone shipping agents without that boundary is basically outsourcing policy to a better worded paragraph, which is a very modern way to get burned.

Read more about this at: WorkOS

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.