When an agent with write access gets audited, what proof do you show?

Exotic-Border-5328 · reddit · 2026-10-02

A solo engineering student asks developers shipping agents with real write access (refunds, CRM updates, code merges) how they answer accountability questions: what was the agent allowed to do at that moment, under which policy, did a human approve it, and was the record later tampered with?

He argues common answers—scoped credentials, human approval, app logs—don't hold up, and describes building a policy gateway in front of tool calls that can allow, deny, or require approval, then signing each decision for later verification.

He asks where guardrails live today, whether anyone has been asked to prove authorization, whether a separate enforcement layer is worth the extra failure point, and at what scale this stops being overengineering.

Original post →

More from coding & agent

coding & agent channel →