Your agent issued a bad refund — who's accountable? A production governance framework

No-Conflict4823 · reddit · 2026-09-30

A Reddit long-form post (by a founder building in this space) tackles accountability when AI agents act: bad refunds, account changes, deleted data.

Key arguments: a prompt is a request, not a permission — "never refund over $100" means little if the agent's credentials allow a $10,000 refund; buying a model doesn't make the vendor responsible for everything you let agents do. For consequential actions the author wants five controls: enforced limits checked at execution, a named approver, least-privilege access with secrets kept out of model context, safe retries (timeouts must not become duplicate payments), and independent, tamper-proof records of authorization and execution. Controls only cover actions that pass through them, so side channels remain a hole. Governance, the author argues, is what makes more autonomy possible — not human approval on every click. Open question: who owns agent authority on your team — engineering, security, or the business owner?

Original post →

More from coding & agent

coding & agent channel →