The demonstration is a scenario. The agent reads the claim, finds the policy, corrects the customer’s address, closes the ticket. Somewhere in the second minute a field in your system of record changed. The room watched it happen and nobody asked the only question that matters in a regulated organisation: who signed that.
Reading is saying; writing is doing
An agent that reads your systems and answers is producing utterances, and an utterance, however fluent, is not a commitment.[1] Nothing binds. If the answer is wrong, someone reads it, and the record is as it was. The moment the agent holds credentials that can write to the system of record, the category changes. The write is an act. It propagates: the nightly job reads it, the invoice carries it, the downstream system trusts it. It binds the organisation and it cannot be unsaid by closing the tab.
That is the entire question with agents in production, and it is asked far too late, usually in the security review after the pilot has been declared a success.
A log is a record of what already happened
The common answer to that question is a log. The agent writes; every write is recorded; an auditor can read the record. The record is honest. It is also useless as a control, because a log describes the past and a control governs the future. By the time anyone reads the entry, the field has changed and the change has travelled.
Reversibility is the condition that separates a draft from a mistake.[2] The risk lives in the execution, which is neither cheap nor revisable; the decision that precedes it is both. Preview, commit, revert. An error caught before the commit is a draft, and a draft is a thing one throws away. An error caught in a log is an incident, and an incident is a thing one explains to a regulator.
Undo is a second write
Vendors know this and offer an undo. Look at what the undo is. It is a second write that restores the previous value, issued after the first write has already propagated. Between the two, the world moved. The customer received the letter, the position was reported, the batch was released. The second write corrects the record; it does not recall the letter.
The only error that can genuinely be reverted is the one that never reached the record. Everything else is remediation with a friendlier name.
The approver who approves three hundred a day
The other answer is a human in the loop. Look at what he does all day. A person validating several hundred machine proposals in a working day validates nothing. He is a signature apparatus attached to a process he cannot examine, and the arrangement exists for the benefit of auditors.[3] Human authority over a system is real only where the proposal is rendered in terms the human understands, is refusable without professional cost, and is reversible after the fact. Bulk approval fails all three: the proposals arrive as a list, the refusal is a delay someone will be asked about, and the batch is committed as one.
A decision with no name at the foot of it is weather.[2:1] A decision with a name obtained by clicking “approve all” is weather with a signature.
What Galahad refuses
The industry’s pattern places the decision in the platform and hands the source system an instruction. An action applied in the platform sends a request to the ERP or the CRM, before the platform’s own change or after it. The pattern is coherent. It also means the system of record receives a call, and what governs that call lives somewhere else.
Galahad refuses three things. An agent with write access and a log as the only control: the log arrives after the act. Approvals in bulk: a hundred proposals in one click is one decision, taken by nobody. An undo that is a second write: reversibility ends at the commit, so the examination has to happen before it.
What remains is the founder’s line: every agent on a harness, every step auditable, every decision traceable. Monarch proposes, it never executes alone. A mistake stays an uncommitted draft.[4] It is what authority has always meant. A vendor who presents it as a concession extracted by regulators has surrendered the argument for nothing.[2:2]
The questions to put to a vendor
Ask them in writing, before the agent is given a credential.
- Which of my systems can the agent write to, and under whose account?
- What does the approver see before the write: the exact change to the record, or a summary the model composed?
- How many proposals does one approver receive per day, and can they be approved as a batch?
- What does it cost the approver to refuse one?
- What is “undo”: the discarding of a draft that never reached the record, or a second write after the first has propagated?
- Whose name is on the write, and can that name be removed afterwards?
A vendor who answers all six with something you can verify from your own network has built a system a regulated organisation can run. A vendor who answers with a log has written the incident report in advance.
Monarch puts every action in front of a named person before it happens, inside your infrastructure, on the systems you already run. See it on your data.