Agent action-class taxonomy
Ten classes of thing an agent can do, and the obligation each one drags in the moment it does it.
Why it exists
Almost every governance argument about agents is conducted at the wrong altitude. Teams debate the model — its accuracy, its provider, whether it hallucinates — while the obligations attach somewhere else entirely: to the action. A regulator does not ask which model declined the claim. It asks who declined the claim, on whose authority, and whether the person affected can find out why. Sorting an estate by action class rather than by model is usually the single change that makes an agent inventory governable, because it produces a list whose rows map one-to-one onto duties that already exist.
What it contains
Ten action classes, ordered by how much of the organisation's authority each one spends
For each: what actually changes at the moment an agent takes it rather than a person
The obligation family it triggers, with the regime that usually carries it
The evidence a reviewer asks for first — and the artifact that closes it
The boundary test that tells you which class a given capability really belongs to
No email required, and nothing is recorded when you download. Use it, adapt it, argue with it — attribution is welcome, not a condition.
The ten action classes
Ordered by escalating authority. An agent almost never sits in one class: classify per capability, not per agent, and inventory the highest class it can reach without a human in the path.
| Class | What it is | What changes when an agent does it | Obligation family | First evidence asked for |
|---|---|---|---|---|
| 01 · Retrieve | Reads and summarises. No writes, no assertions to a third party. | Agents retrieve broadly to answer narrowly. The access pattern inverts: where a person opened three records, an agent opens three hundred and uses four. | Access control, minimum necessary, purpose limitation. HIPAA Security Rule §164.312; India DPDP purpose limitation. | Access logs at the volume an agent actually generates, and the entitlement that scoped the query. |
| 02 · Assert | States something a counterparty can act on — a policy, an entitlement, a fact about their account. | The statement becomes the organisation's statement. Moffatt v. Air Canada (2024 BCCRT 149) settled that the argument 'the chatbot said it, not us' does not survive. | Misrepresentation, conduct, consumer protection. | What the agent said, to whom, and what the authoritative source said at that moment. |
| 03 · Recommend | Produces an output a human is expected to act on, without acting itself. | The human-in-the-loop defence only holds if the human had the material and the time. An approver clicking through at nine seconds per case is a rubber stamp with an audit trail. | Model risk, effective challenge, clinical-decision-support boundaries. Federal Reserve SR 11-7 (2011). | What the reviewer was shown, what they decided, and how long they had. |
| 04 · Commit | Binds the organisation — a quote, a promise, a service commitment, a term. | Authority to bind is a well-understood legal concept that almost nobody has mapped onto a non-human actor. Delegated underwriting authority is the closest existing analogue. | Contract formation, delegated authority, producer conduct. | The grant that authorised a commitment of that size, in that class, at that moment. |
| 05 · Transact | Moves value: payments, limits, pricing, reserves, positions. | The blast radius stops being reputational. Controls designed around a human's rate of work — four eyes, daily limits, batch review — do not survive an actor operating at machine rate. | Payment controls, segregation of duties, model risk, fraud and AML. | The value and rate limits actually enforced at the point of action, not the ones in the policy. |
| 06 · Mutate record | Writes to a system of record: claims, patient, customer, ledger. | The record becomes evidence in someone else's proceeding. Integrity and attribution now matter more than accuracy. | Records integrity and attribution. 21 CFR Part 11 for regulated records; books-and-records duties. | An immutable event tying the change to the agent, the authority and the input that justified it. |
| 07 · Configure | Changes a control: a threshold, a rule, an entitlement, a routing decision. | The agent is now acting on the control plane rather than inside it. A system that can widen its own limits has no limits. | Change management, segregation of duties, control self-assessment. | Change records with approval, and proof the agent cannot alter the controls that bind it. |
| 08 · Delegate | Invokes another agent or tool, or grants authority onward. | Authority becomes transitive. Most stacks cannot answer which human's grant a third-hop tool call was ultimately spending. | Delegation chain, sub-processing, third-party risk. OCC 2023-17; NYDFS Part 500.11 (scoped to access). | A machine-readable chain from the accountable human to the executing call. |
| 09 · Communicate externally | Sends to a customer, counterparty, or a regulator. | Everything sent is disclosable and retained. Language, channel and timing all acquire obligations. | Conduct, disclosure, retention. CBUAE AI/ML Guidance Note §4b expects Arabic and English disclosure for UAE licensed institutions. | The full outbound record, retained for the regime's period, not the application's default. |
| 10 · Deny or terminate | Refuses service, declines a claim, closes an account, rejects an application. | This is the class that creates a person with a grievance and a right. It is also the class most often built first, because refusal feels safer than approval. | Adverse action, fairness, appeal and human-review rights. CBUAE §7c; EU AI Act Annex III where applicable. | A reconstructable reason in the terms the affected person is entitled to receive. |
Boundary tests — which class does this capability really belong to?
Applied in order. The first test that returns yes sets the class; capabilities are routinely classified a tier too low.
| Ask | If yes |
|---|---|
| Can its output reach a person outside the organisation without a human reading it first? | At least Assert. Not Retrieve. |
| Would a reasonable recipient rely on it? | At least Assert, and probably Commit. |
| Does anything change in a system other people read as true? | At least Mutate record. |
| Does money, a limit, a price or a reserve move? | Transact, regardless of size. |
| Can it change a threshold, rule or permission — including its own? | Configure. Treat as the highest tier present. |
| Can it call something that can do any of the above? | It inherits that class. Authority is transitive; classification has to be too. |
| Is there a human approval step? | It only lowers the class if you can evidence what the approver saw and how long they had. |
How to use it
- List capabilities, not agents. One agent commonly spans four classes.
- For each capability, run the boundary tests in order and record the first yes.
- Take the highest class reachable without a human in the path — that is the agent's governing class.
- Map that class to the obligation family, then to the specific regime that binds you.
- Where the evidence column names something you cannot produce today, that is the gap. Record it as such rather than restating the policy.
- Re-run when a tool is added. Adding one integration can move an agent two classes.
Built from public standards and general practice. Regulatory instruments move — check anything cited here against its primary source on the day you rely on it. Related: the other artifacts · the diagnostic.
Want this applied to your architecture?
The artifacts are general by design. Applying one to a specific estate is what the governance review does.