Tool access becomes inherited authority
An agent that can see credentials, APIs, files, CRM records, or infrastructure should not automatically gain permission to change them.
ARBITER · AI ACTION CONTROL
INTIGNAI ARBITER sits between AI intent and consequential action. It keeps context separate from authority, applies deterministic policy, requests human approval only when required, constrains the approved action, and returns an Outcome Receipt.
THE OPERATING PROBLEM
An agent that can see credentials, APIs, files, CRM records, or infrastructure should not automatically gain permission to change them.
If every action asks for a click, people stop inspecting. Gates should focus human attention on consequential state changes and bind approval to the exact action being reviewed.
Audit trails are useful, but they do not stop an unauthorized send, payment, delete, command, or configuration change before it happens.
CONTROL BEFORE AUTONOMY
The approved object is the specific target, operation, parameters, policy state, and risk state—not a vague standing instruction.
Execution authority can be constrained to one approved action, adapter, resource, time window, and policy envelope instead of handing the model durable credentials.
Consequential execution closes with evidence of what was requested, allowed, executed, returned, denied, expired, or failed so operators can reconstruct truth.
VERIFY IT
Proof One demonstrates the control boundary directly: useful AI context can exist without silently becoming execution permission, and consequential work closes with inspectable evidence.