Trust
Permissioning that inherits scope, gates on irreversible actions, and an audit trail counsel can reconstruct — the bar for agents inside an enterprise.
2026-07-15 · By MCV.TECH Editorial Team · Trust
"Counsel-grade" gets used as decoration often enough that it is worth saying plainly what we mean by it. We mean a specific, testable standard: work that an enterprise's own counsel can review after the fact, reconstruct from durable records, and defend — without taking the vendor's word for any of it.
The standard matters most exactly where software is heading. When agents act inside an enterprise — reading operational state, proposing actions, executing them — the legal question stops being "what does the tool do?" and becomes "can we show what was done, by what authority, on whose data?" Three properties follow.
An agent acting for an operator must see exactly what that operator may see — no more. Brand and location context is explicit and inherited from the invoking session, never inferred from a URL, a prompt, or a previous task. If the operator cannot open a record in the console, the agent working on their behalf cannot open it either.
This sounds obvious and is routinely violated. Tools that keep their own credential stores, or that broaden scope "for context," create a second permission system shadowing the real one — unaudited, and usually invisible to the people who approved the first. Counsel-grade means there is one permission system, and agents live inside it.
Not every action deserves a committee. Reads, analysis, and reversible proposals can move at machine speed. But actions that cannot be undone — payments issued, records deleted, terms sent externally, permissions changed — sit behind explicit human approval gates, and the gate decision is itself recorded.
Two things make a gate real. The list of gated actions is operator policy — visible and changeable by the operator, not a vendor default buried in a model. And the gate fails closed: an expired or unanswered approval blocks the action rather than releasing it. An agent that can do something irreversible without a gate is not autonomous; it is unsupervised.
The record for any agent action answers, durably: what the agent observed, what it proposed, which policy applied, who approved, what executed, and what happened. "Durably" means the record survives log rotation, staff turnover, and the end of the vendor relationship.
The test is reconstruction. A year from now, counsel should be able to sit down with the record and rebuild the incident, the quarter, or a divested brand's history — from evidence, not from anyone's memory. Including ours.
This is also the part that cannot be bolted on later. An audit trail assembled after the fact, from logs that were never designed to answer legal questions, is a narrative. A trail written at the moment of action — proposal, policy, approval, outcome — is evidence. Enterprises buying agents today are really buying the second thing, whether or not the demo mentions it. How the record is produced and preserved is documented at the audit trail & evidence model.
It is not a certification logo, a promise that nothing will ever go wrong, or a synonym for "enterprise." It is a property of the record, and it is checkable. Ask any vendor — us included — to reconstruct one specific action from a year ago. The answer, or the pause before it, is the diligence result.
How multi-unit operators actually adopt a Business OS: one bounded workflow, explicit proof criteria, then expansion on evidence. · Source · CMS snapshot (seed).
A measured Business OS rollout starts with decisions, owners, evidence, and review gates — not a portfolio-wide switch-flip.
Useful agents act inside explicit scope, policy, approvals, and evidence trails while human operators retain the gates.