Reference taxonomy

Agent action-class taxonomy

Ten classes of thing an agent can do, and the obligation each one drags in the moment it does it.

Why it exists

Almost every governance argument about agents is conducted at the wrong altitude. Teams debate the model — its accuracy, its provider, whether it hallucinates — while the obligations attach somewhere else entirely: to the action. A regulator does not ask which model declined the claim. It asks who declined the claim, on whose authority, and whether the person affected can find out why. Sorting an estate by action class rather than by model is usually the single change that makes an agent inventory governable, because it produces a list whose rows map one-to-one onto duties that already exist.

What it contains

01

Ten action classes, ordered by how much of the organisation's authority each one spends

02

For each: what actually changes at the moment an agent takes it rather than a person

03

The obligation family it triggers, with the regime that usually carries it

04

The evidence a reviewer asks for first — and the artifact that closes it

05

The boundary test that tells you which class a given capability really belongs to

No email required, and nothing is recorded when you download. Use it, adapt it, argue with it — attribution is welcome, not a condition.

Reference taxonomy · v1.0 · 24 July 2026

The ten action classes

Ordered by escalating authority. An agent almost never sits in one class: classify per capability, not per agent, and inventory the highest class it can reach without a human in the path.

ClassWhat it isWhat changes when an agent does itObligation familyFirst evidence asked for
01 · RetrieveReads and summarises. No writes, no assertions to a third party.Agents retrieve broadly to answer narrowly. The access pattern inverts: where a person opened three records, an agent opens three hundred and uses four.Access control, minimum necessary, purpose limitation. HIPAA Security Rule §164.312; India DPDP purpose limitation.Access logs at the volume an agent actually generates, and the entitlement that scoped the query.
02 · AssertStates something a counterparty can act on — a policy, an entitlement, a fact about their account.The statement becomes the organisation's statement. Moffatt v. Air Canada (2024 BCCRT 149) settled that the argument 'the chatbot said it, not us' does not survive.Misrepresentation, conduct, consumer protection.What the agent said, to whom, and what the authoritative source said at that moment.
03 · RecommendProduces an output a human is expected to act on, without acting itself.The human-in-the-loop defence only holds if the human had the material and the time. An approver clicking through at nine seconds per case is a rubber stamp with an audit trail.Model risk, effective challenge, clinical-decision-support boundaries. Federal Reserve SR 11-7 (2011).What the reviewer was shown, what they decided, and how long they had.
04 · CommitBinds the organisation — a quote, a promise, a service commitment, a term.Authority to bind is a well-understood legal concept that almost nobody has mapped onto a non-human actor. Delegated underwriting authority is the closest existing analogue.Contract formation, delegated authority, producer conduct.The grant that authorised a commitment of that size, in that class, at that moment.
05 · TransactMoves value: payments, limits, pricing, reserves, positions.The blast radius stops being reputational. Controls designed around a human's rate of work — four eyes, daily limits, batch review — do not survive an actor operating at machine rate.Payment controls, segregation of duties, model risk, fraud and AML.The value and rate limits actually enforced at the point of action, not the ones in the policy.
06 · Mutate recordWrites to a system of record: claims, patient, customer, ledger.The record becomes evidence in someone else's proceeding. Integrity and attribution now matter more than accuracy.Records integrity and attribution. 21 CFR Part 11 for regulated records; books-and-records duties.An immutable event tying the change to the agent, the authority and the input that justified it.
07 · ConfigureChanges a control: a threshold, a rule, an entitlement, a routing decision.The agent is now acting on the control plane rather than inside it. A system that can widen its own limits has no limits.Change management, segregation of duties, control self-assessment.Change records with approval, and proof the agent cannot alter the controls that bind it.
08 · DelegateInvokes another agent or tool, or grants authority onward.Authority becomes transitive. Most stacks cannot answer which human's grant a third-hop tool call was ultimately spending.Delegation chain, sub-processing, third-party risk. OCC 2023-17; NYDFS Part 500.11 (scoped to access).A machine-readable chain from the accountable human to the executing call.
09 · Communicate externallySends to a customer, counterparty, or a regulator.Everything sent is disclosable and retained. Language, channel and timing all acquire obligations.Conduct, disclosure, retention. CBUAE AI/ML Guidance Note §4b expects Arabic and English disclosure for UAE licensed institutions.The full outbound record, retained for the regime's period, not the application's default.
10 · Deny or terminateRefuses service, declines a claim, closes an account, rejects an application.This is the class that creates a person with a grievance and a right. It is also the class most often built first, because refusal feels safer than approval.Adverse action, fairness, appeal and human-review rights. CBUAE §7c; EU AI Act Annex III where applicable.A reconstructable reason in the terms the affected person is entitled to receive.

Boundary tests — which class does this capability really belong to?

Applied in order. The first test that returns yes sets the class; capabilities are routinely classified a tier too low.

AskIf yes
Can its output reach a person outside the organisation without a human reading it first?At least Assert. Not Retrieve.
Would a reasonable recipient rely on it?At least Assert, and probably Commit.
Does anything change in a system other people read as true?At least Mutate record.
Does money, a limit, a price or a reserve move?Transact, regardless of size.
Can it change a threshold, rule or permission — including its own?Configure. Treat as the highest tier present.
Can it call something that can do any of the above?It inherits that class. Authority is transitive; classification has to be too.
Is there a human approval step?It only lowers the class if you can evidence what the approver saw and how long they had.

How to use it

  1. List capabilities, not agents. One agent commonly spans four classes.
  2. For each capability, run the boundary tests in order and record the first yes.
  3. Take the highest class reachable without a human in the path — that is the agent's governing class.
  4. Map that class to the obligation family, then to the specific regime that binds you.
  5. Where the evidence column names something you cannot produce today, that is the gap. Record it as such rather than restating the policy.
  6. Re-run when a tool is added. Adding one integration can move an agent two classes.

Built from public standards and general practice. Regulatory instruments move — check anything cited here against its primary source on the day you rely on it. Related: the other artifacts · the diagnostic.

Next step

Want this applied to your architecture?

The artifacts are general by design. Applying one to a specific estate is what the governance review does.