Agent Auth Desk

Wayne Payments, checkout-service

An agent ships a fix, and every move it makes asks am I allowed to do this?

One coding agent, one bug report, one repository. It reads the code, writes the patch, runs the tests, opens the pull request and tries to release. Each of those is a live authorization check against a WorkOS staging environment before the tool runs, and an audit log event after. Change which grants the agent holds and run it again: the code is identical, the run is not.

Live checks this session: 0 Median check round trip: waiting Audit events written: 0
Runs under

Agent identity WorkOS staging

Waitingrun the agent

Resource hierarchy organization is the root

The two policies same code, different grants