Where should agent action authorization live? AI support teams debate refund safety policies

witty_queen123 · reddit · 2026-09-21

Teams running AI support agents face a core engineering question: when an agent can take real actions like issuing refunds, where should the safety policy live?

The author's example policy:

Should this policy sit in the agent prompt, the tool, the backend, or a separate authorization service? The author is exploring whether "agent action authorization" deserves to be its own infrastructure layer and is soliciting lessons from teams that have shipped it.

Original post →

More from coding & agent

coding & agent channel →