The teardown that precedes this one ends with an instruction rather than an argument. Take one production agent. Put its credentials on one page. Mark each one read or write, network or record or subscriber, and whether any write path executes without a human decision. Then ask who, if anyone, ever saw that page as one thing.
Assume somebody did it. This piece is about the morning after.
The page comes back and it is worse than expected, in the specific way that competent organisations produce bad news: nothing on it is wrong. A regional operator has nine agents in production across its network operations estate. The fault-remediation agent holds five credentials. The energy-saving scheduler holds two. The capacity planner holds one. The complaint-triage agent holds two, one of which reaches subscribers. The neighbour-list optimiser holds two, one of which writes parameters across the whole element-manager domain because that is the only scope an orchestration service account comes in. Every credential on the page was provisioned by a named person against an approved request. Every one of them was reviewed.
Then somebody at the table asks the question the page was assembled to answer, and the page cannot answer it: which of these agents is allowed to change the network at six o'clock on a Friday evening?
Not because the answer is bad. Because the page has no column it could go in. The vocabulary the operator's platform provides is connector, grant, principal, scope. None of those words has an order in it, and the question is a question about order — about which of these things is more dangerous than which other thing, and under what conditions the ordering changes.
The nine agents, the five credentials, the domain scopes and the register in the figures below are a constructed illustration. They are assembled from mechanisms documented in public network-management architectures and from operators' own published descriptions of their agent programmes. No part of this is a client engagement, a disclosed incident, or a description of any named operator's estate, and the numbers in the figures are illustrative rather than measured.
So the construction begins there, with the thing the page is missing, which is not more fields. It is a vocabulary with an ordering in it, denominated in the units this sector's harm is actually measured in, and computed from what the agent holds rather than asserted about what the agent is for.
What the class has to be denominated in
Start with the units, because getting them wrong imports the wrong construction from a neighbouring sector and the mistake is invisible until it is expensive.
In the sectors where this argument was first made — banking, insurance, health — blast radius is denominated in records. How many customers' data did the agent touch. How many accounts did it adjust. How many claims did it decide. The unit is a countable set of subjects, the harm is disclosure or incorrect treatment, and the remediation clock is measured in days to weeks. That denomination is why those sectors' controls look the way they do, and it is why minimum-necessary scoping is the natural primitive there: fewer records is straightforwardly less harm.
A radio access network does not work like that. A mis-scoped write to a neighbour list does not leak anything. It drops calls, for everyone in the cell's coverage, for as long as the change stands. The subjects are not enumerable in advance because they are whoever happened to be in the coverage area, the harm is unavailability of a physical service rather than exposure of a record, and there is no notification clock because there is nothing to notify — the affected population experienced it in real time and formed its own opinion.
The reach of a credential here is a physical quantity, and the operator already computes it. This is the fortunate part. An operator does not need new telemetry to denominate blast radius, because it already knows, per cell, the coverage footprint, the attached-subscriber counts across the day, the traffic profile, and which cells carry disproportionate load at which hours. That data exists for capacity planning and it exists for the availability commitments the operator already reports against. The reach of a configuration credential is the union of those quantities across every cell the credential can write to. It is arithmetic over facts the operator holds, not a new measurement programme, and the fact that nobody currently computes it for a credential is an accident of which team owns which table.
The unit that does not transfer is the record count. A KPI read across nine hundred cells exposes topology and performance data, which is a real if modest exposure, and a record-denominated scheme would rank it above a write to forty cells because the read touches more rows. That ranking is exactly backwards for this sector. Any classification built on volume of data touched will systematically under-rank the write path, which is the only path that can take a service away from a population. The denomination has to be what the mis-scope costs the network, and reads and writes cannot be priced on the same axis.
There is a second dimension, and it is the one that makes telecom's version of this problem different even from other physical-infrastructure sectors. Some credentials do not reach the network at all; they reach the subscriber directly, through the messaging gateway. That reach is not availability and it is not data volume. It is contact — an outbound communication to a named person, in a jurisdiction that may regulate exactly that. It belongs on the manifest as its own kind of reach, and the reason will become concrete when the composition rules arrive.
The capability manifest
The manifest is the page from the teardown, formalised into something that can be a control rather than an exercise. It is one row per credential the agent holds, and it carries five things per row.
- The credential, as the platform knows it. The connector, the integration, the service account, the token audience — whatever the grant surface's own identifier is, so the row can be traced back to the provisioning record without a human translating.
- The grant as provisioned, in full. Not the scope the agent was intended to use. The scope the credential actually carries, which for most network integrations is the domain rather than the target, because element managers and orchestration APIs do not issue per-cell credentials and nobody should pretend otherwise.
- The direction. Observe, act, author-record, or reach-subscriber. Four values, deliberately few, because the composition rules operate on these and a taxonomy with fifteen values produces rules nobody can evaluate.
- The reach, in network units. For an act credential: the cells it can write to, the subscribers in their coverage, the services affected. For an observe credential: what it exposes. For a reach-subscriber credential: the addressable population and the communication categories available to it.
- The class the row implies on its own. Before composition. This is the number the composition rules take as input, and it is the only field on the row that is derived rather than read.
The single most important property of the manifest is that it is derived and not declared. A manifest written by the team that built the agent is a document — it records what they believe the agent holds, which is what they intended it to hold, which is the thing the teardown showed to be systematically different from what it actually holds. A manifest generated from the platform's grant state on a schedule is a control, because the generation is what catches the fifth connector that somebody enabled on a Thursday.
The generation is the whole control, and everything downstream is presentation. The operator's platform already knows which connectors are enabled for which agent runtime, and its identity provider already knows what each service account can reach. The manifest is a join over two tables the operator maintains for other reasons. Run it nightly, store the result, and diff it. A row that appears without a corresponding decision is the alert, and it is very nearly the only alert this control needs to emit — because the failure mode the teardown identified is not a bad decision, it is an absent one, and an absent decision shows up as a diff with no ticket behind it.
Two practical notes, because this is the part people get wrong when they build it. First, the manifest must be per-runtime rather than per-agent-definition: two deployments of the same agent in different regions hold different scopes, and merging them into one row hides exactly the variance the control exists to surface. Second, credentials acquired at run time — a token minted mid-plan, a secret read from a store — belong on the manifest as capabilities the agent can obtain, not as absences. If the agent can reach the store, it holds everything in the store, and a manifest that lists the connector but not the store's contents will pass an inspection it should fail.
Four classes, and the arithmetic between them
Now the ordering. Four classes, defined by what a mis-scope costs, and defined so that the boundary between each pair is a single, checkable question rather than a judgement.
- C0, read. The agent observes: KPIs, alarms, topology, inventory. A mis-scope exposes performance and topology data to a system that should not have had it. There is no path from this class to a service effect, which is the definition rather than an observation about the current implementation.
- C1, recommend. The agent produces a proposed change into a queue that a person works. A mis-scope wastes operator attention and, over time, erodes trust in the queue — a real cost, and not a service cost. The boundary question between C1 and C2 is exactly one: is there any path by which the agent's output reaches the network without a person deciding this action.
- C2, execute with a gate. The agent's proposal executes only after a named person decides. A mis-scope can reach service availability, but only through that person, and the bound on the damage is the quality of their scrutiny — which is a real bound, and a decaying one, and the decay is why C3 exists as an honest category rather than a forbidden one.
- C3, autonomous within a window. The agent executes with no per-action human decision, inside an issued window bounded by time, network scope and conditions. A mis-scope reaches service availability across the window's scope at machine rate. This is a legitimate class. Some remediation genuinely must run faster than a person can be found, and pretending otherwise produces a control that gets routed around.
The ordering matters more than the labels. Labels are a taxonomy; an ordering is an arithmetic, and an arithmetic is what lets you compute the class of a set from the classes of its members. That computation is the thing the operator's two pipelines cannot do, because neither of them ever holds a set.
Three rules operate on the held set. Each one is a rule about what capabilities become when they are held together, and each one is the formal statement of a mechanism the teardown described in prose.
Rule one: observation plus execution over the same domain is one rung higher than either. An agent that can see the network and change the network chooses its own trigger. Nothing external decides when it acts; the decision to act is a function of what it observed, evaluated inside the same process. That is a closed loop, and a closed loop at C2 behaves like a C3 system whenever the gate is nominal — which is to say, whenever the operator has been accepting recommendations for a few months. Rather than argue about whether a particular gate is real, class the loop a rung above the higher of its parts and let the operator justify the higher class or break the loop. Breaking it is cheap: the observation credential and the execution credential in different principals, with the proposal crossing between them as data, costs one queue.
Rule two: execution plus authorship of the record of that execution has no class until the pair is split. This is the sector-specific invariant and it is the one I would enforce hardest, because the change record is the artefact the operator's entire assurance posture rests on. When the actor writes the record, the record continues to satisfy every downstream consumer — the audit sampler, the post-incident review, the outage enquiry — and stops being evidence, silently, with no signal anywhere that anything changed. The rule is therefore not an escalation but a refusal: the composition is not assigned a class, the manifest marks it disqualifying, and the deployment is blocked until the record-authorship credential sits with a principal that holds no execution credential over the same domain. This costs one service account and an hour of plumbing, which is a low price for the difference between paperwork and evidence.
Rule three: execution plus subscriber outreach is defined only where the category determination is made in advance. An agent holding both the network path and the messaging gateway decides, per event, whether to tell subscribers and what to say. In India that decision instantiates the consent and preference categories of TCCCPR 2018 as amended in February 2025 — historically a judgement made by an accountable campaign owner who answered for it. The construction does not try to teach the agent the categories. It removes the judgement from run time: the agent may send only from a pre-registered template set, each template bound in advance to a category by a named owner, with free composition unavailable. If the operational need cannot be met from the template set, the outreach capability is withheld and a person sends the message. The design principle is general even though the instrument is not: where a capability crosses a regulated boundary, the crossing is decided in advance by someone who can be asked why.
Window-scoped autonomous grants
C3 is the class the whole construction exists to make safe, because C3 is where the value is. Hours to a minute, in the operators' own announcements, is a story about removing the human gate between diagnosis and action. A control regime that answers by putting the gate back has not solved the problem; it has declined it, and the programme will route around it within two quarters.
So C3 stays. What changes is that a C3 capability exists only inside an issued window, and the window is an object rather than a configuration predicate.
- A time interval. When the autonomy applies. This is the part every operator already has, because it is the maintenance window, and it is the only part of the window that current implementations represent at all — usually as a cron expression in the agent's configuration rather than as anything in the grant.
- A network scope. Which cells, sites or parameter families. Named, enumerable and narrower than the credential's provisioned domain, which means the window is doing work the credential cannot do on its own: the orchestration API's account can write everywhere, and the grant says it may write here.
- A condition predicate. The states under which the autonomy is valid. No active major incident, traffic below a stated threshold, no event in the venue calendar within the coverage area, no concurrent planned works on the same corridor. Written down, in the grant, in a form something other than the agent can evaluate.
- Two exits. Expiry on the clock, and expiry on condition change. The second one is the one that is always missing, and it is the one that carries the safety property: the moment the measured state leaves the predicate, the window closes, whatever the clock says.
- An issuer and a revocation handle. A named person issued it, and one call withdraws it — this window, this class, this scope — without severing the account and taking every correctly-behaving pathway down with it.
The window is not an import from software. It is this industry's own invention, moved one layer. Every element of the object above already exists in the operator's change discipline. A method of procedure names the apparatus. A change window names the hours. A change advisory board's approval carries conditions — do not proceed if the region is in a major incident, do not proceed during the match. A change is revocable in the sense that it has a rollback plan and a named owner who can call it. The construction adds nothing conceptually. It moves the object from the change pipeline, where it binds a single intended action, to the capability layer, where the agents actually live — which is the transposition the teardown said had not happened.
The condition exit is what makes the grant a grant rather than an entitlement with a timer. A window that expires only on the clock is a standing capability with a schedule attached, and the sector's own risk calculus was never purely temporal: the same parameter push is routine at two in the morning on a Tuesday and reckless at two in the morning during a national event or an ongoing incident. Representing the condition in the grant, and evaluating it somewhere other than inside the agent, is the difference between an envelope that is asserted and an envelope that is enforced. It is also the cheapest place to get this wrong — an implementation that evaluates the predicate using the agent's own view of the network has built a system that decides for itself whether it is allowed to act.
Where the predicate is evaluated is therefore load-bearing, and the answer is: at the point that dispatches to the network, using a state source the agent did not produce. In most operator estates that is the orchestration layer or the change-execution gateway, not the agent runtime and not the platform that hosts it. This is the same architectural instinct that says a resource server should check the token rather than trusting the client to have checked it, and it is the property most likely to be traded away during implementation because it requires a team that does not own the agent to make a change.
The manifest, the class arithmetic, and the window grant
Three files in the order they would be built. The first is the manifest row, typed so that reach is not optional and direction is a closed set. The second computes the class of a held set and returns a disqualification rather than a number where an invariant fails — the type makes it impossible to obtain a class for a composition that should not ship. The third is the window grant and the check that belongs at the dispatch point rather than in the agent. None of this is production code; it is the data model stated precisely enough to argue with.
Note that reach is required and that it is a union rather than a number: an observe credential and an act credential cannot be compared on one scale, and forcing them onto one is the error that imports a record-denominated scheme into a service-denominated sector.
/** The four directions a network credential can point. Deliberately few. */
export type Direction = "observe" | "act" | "author-record" | "reach-subscriber";
/** Reach is denominated differently per direction, because the harms are not commensurable. */
export type Reach =
| { readonly kind: "observe"; readonly exposes: readonly string[] }
| {
readonly kind: "act";
/** Cells the credential can write to, as provisioned — not as intended. */
readonly cellCount: number;
/** Subscribers in the coverage of those cells, at the busy hour. An estimate; see the body. */
readonly subscribersInCoverage: number;
readonly servicesAffected: readonly string[];
}
| { readonly kind: "author-record"; readonly recordSystem: string }
| {
readonly kind: "reach-subscriber";
readonly addressablePopulation: number;
/** Empty means the agent composes messages freely at run time. That is the finding. */
readonly preRegisteredTemplates: readonly string[];
};
export interface ManifestRow {
/** The platform's own identifier, so the row traces back to a provisioning record. */
readonly credentialId: string;
readonly connector: string;
readonly direction: Direction;
/** The scope the credential carries, not the scope the agent was meant to use. */
readonly provisionedScope: string;
readonly reach: Reach;
}
export interface AgentManifest {
/** Per runtime, never per agent definition: two regions are two manifests. */
readonly runtimeId: string;
readonly agentName: string;
readonly environment: "production" | "pre-production";
readonly rows: readonly ManifestRow[];
/** When the manifest was derived from platform state. A stale manifest is a document. */
readonly derivedAtIso: string;
}These files describe a data model, not a deployment. They are written to be read and argued with rather than run, and they omit everything an implementation needs — persistence, revocation propagation, clock skew, and the question of what the dispatch point does when its own state source is stale, which is the first hard problem an implementer will meet.
The register, and who owns it
The manifest is per agent. The register is the fleet: which class every production agent sits in, on what network scope, under which windows, with which invariants passing. It is the object the composition review reviews, and its existence is the answer to the structural finding in the teardown — that the composed capability arrives in no queue. Give it a queue by giving it an object.
Three properties make the register a control rather than an inventory. It is derived on a schedule from the platform's own grant state, so it cannot drift from reality without the drift showing as a diff. It carries the invariant checks inline, so a failing composition is visible on the same page as the classes rather than in a separate assurance report nobody opens. And it is small — a fleet of nine agents fits on one screen, which matters more than it sounds, because a control that requires a tool to read will be read by whoever owns the tool and by nobody else.
Ownership is the part that decides whether any of this survives. The register cannot belong to the agent teams, because it exists to check them, and it cannot belong to platform onboarding, because onboarding's mandate ends at publication and the register's subject is what happens after. The natural owner is the function that already owns network change risk — the change authority, the design authority, whatever the operator calls the body that says yes to a method of procedure — because that function already holds the only relevant expertise, which is knowing what a parameter family can do to a cell. Giving it a new input shape is a smaller organisational change than creating a new review body, and it is the change most likely to actually happen.
The cadence I would argue for is weekly for the diff and quarterly for the classes. The diff is cheap and catches the connector enabled on a Thursday. The class review is expensive and catches the slower failure — an agent whose scope grew, or whose gate stopped being real, without any single change looking like a promotion.
The bill
Every construction has costs, and the ones that get built are the ones whose authors were honest about them early. Five, at full strength.
It spends latency, and it spends it in exactly one place. The teardown's closing note is the constraint: hours to a minute is the value proposition, and every gate between diagnosis and action spends what the programme was funded on. This construction spends nothing at C0 and C1, spends nothing at C3 beyond one predicate evaluation at dispatch — microseconds against a change that takes seconds to propagate — and spends real time only at C2, where a person is in the path by definition and was already the latency. What it does spend everywhere is deployment friction: the invariants fail closed, so a composition that trips rule two does not ship on Friday. That is a genuine cost and I would not trade it away, but calling it free would be dishonest.
The reach figures are estimates, and estimates in a control tend to harden into facts. Subscribers in coverage is not a measured quantity; it is a modelled one, varying by hour, by day and by whatever is happening in the coverage area, and the number that lands in the manifest will be a busy-hour figure from a planning tool. That is fine for ordering — it is reliably right about which of two credentials reaches further — and it is not fine for anything that looks like a risk quantification. I would carry the figure with its basis attached and refuse to let it into any calculation that multiplies it by a cost, because the moment it appears in a spreadsheet with a currency column it will be defended as a measurement by someone who was not in the room when it was produced.
Classification schemes rot, and this one will rot in a specific way. Every scheme with a dangerous top class develops pressure to classify downward, and the pressure arrives as a reasonable argument: this write is only to a parameter that cannot affect service, so it should be C1. Sometimes that is true. The defence is that class is derived from direction and reach rather than argued, so relabelling requires changing what the credential can reach, which is a provisioning change with a record. The residual risk is the direction field, which is the one human judgement left in the derivation — someone decides that a given connector is act rather than observe — and I would expect that field to be where a determined team applies pressure. Auditing it is a sampling exercise on a handful of rows per quarter, which is cheap enough that there is no excuse.
Rule two cannot be enforced across a vendor boundary, and the vendor boundary is where the agents come from. If the RAN vendor ships an agent that executes changes and files its own tickets in the vendor's own workflow system, the operator cannot split the pair by moving a credential, because the composition is inside a product. The available responses are contractual — require the record path to terminate in the operator's system of record, written by a principal the operator provisions — and architectural, which means the operator's own gateway writes the record on execution rather than accepting one from the agent. The second is better and is only available to operators who own the dispatch point. Operators who have outsourced the dispatch point have a procurement problem rather than an engineering one, and I would rather say that plainly than pretend the construction reaches it.
Nothing here is required by any instrument, and the argument does not improve if you pretend otherwise. As of June 2026, India — a market with some of the fastest operator adoption anywhere — has no AI-specific telecom regulation in force. The FCC's declaratory ruling of 8 February 2024 confirmed that AI-generated voices fall within the TCPA's definition of an artificial or prerecorded voice, which governs what an AI voice may say into a subscriber's ear and says nothing about what an AI system may do to a cell site. The one instrument that touches anything in the manifest is TCCCPR 2018 and its February 2025 Second Amendment, and it touches the outreach flank only. So this construction is not a compliance deliverable. It is an engineering answer to a question the operator will be asked by its own board, its own enterprise customers, and eventually by whoever drafts the instrument — and the last of those is the reason to build it now rather than later, because the drafters will look at what operators built.
What would falsify this
Three things would show the design wrong rather than merely incomplete, and I would rather name them than be shown them.
If the ordering does not survive contact with real estates. The whole construction rests on the claim that four classes with three composition rules can be applied to a real agent fleet and produce answers the operator's own network engineers recognise as correct. If applying it to a live estate produces a large residue of agents that clearly do not fit — if half the fleet lands in C2 with arguments attached, or if the direction field turns out to be genuinely ambiguous for most network integrations rather than for a few — then the taxonomy is wrong and needs to be rebuilt from what the residue looks like. I have applied it only to constructed estates, and constructed estates are obliging.
If the condition predicate cannot be evaluated where I have put it. The safety property depends on the dispatch point holding a network state view independent of the agent, current enough to be meaningful at the moment of the command. If in real operator architectures the only party with a fresh consolidated state view is the same platform that hosts the agent, then the independence I am relying on is notional and the design needs a different verifier — perhaps the element manager itself, at a cost in per-vendor implementation that might make the whole thing impractical. This is the assumption I am least confident about and the one I would test first in any real engagement.
If an operator is already doing this and calls it something else. The most likely way this piece is wrong is that some tier-one operator's network design authority has, quietly, built a capability register with a risk ordering on it, and simply has not published because operators publish very little architecture. If that exists, the contribution here is at best a vocabulary, and the right response is to go and read theirs. I would take that outcome cheerfully; the argument I actually care about is that the object should exist, not that this particular shape of it is the one.
One thing this construction does not do, stated plainly because the omission is easy to miss. It bounds what an agent may reach and records what it was permitted to do. It does not make the agent's decisions good. A perfectly classed, correctly windowed, invariant-passing C3 agent that recommends a bad parameter change inside its scope will make the change, and the register will show, accurately, that everything was in order. Blast-radius classes are a containment control, not a quality control, and anybody selling them as safety is selling the wrong property — which is the same caution that applies to every attestation layer, in every sector this series has looked at.
The smallest version that is worth building is smaller than everything above. Derive the manifest for one agent from platform state, by script, once. Add the two columns the grant surface does not carry. Run the three rules by hand. If the result is boring, the estate is in better shape than the teardown suggests and the exercise cost an afternoon. If the result is not boring, the register has already paid for itself before anybody has written a line of the control.