Execution Authority · Pattern library
The same risky actions, in every company.
A pattern is a shape of risky execution that recurs regardless of industry — an action that spends money nobody approved, a deploy that assumes a review it never had, an agent that reaches data it should not keep. 15 patterns, each with the signals that decide it and, where the evaluator ships one, the policy pack whose rules decide it.
Showing the patterns that most often bite in Healthcare. They are the same patterns — the filter narrows the library, it does not change what a pattern is.
Protecting money
Payments, payouts, refunds, spend and treasury movement.
Protecting infrastructure
Production data, cloud resources, secrets and network egress.
Control MCP egress
Decide what leaves before it leaves, at the tool-call boundary.
Its gate and signals
Prevent destructive production changes
Make deleting production a decision, not a command.
1 policy pack
Third-party data sharing
Decide what reaches an external system before the request is made.
Its gate and signals
Protecting ai agents
Tool calls, retrieval, memory and autonomous action.
Protecting approvals
Delegated authority, segregation of duties and escalation paths.
Protecting identity
Access grants, privilege, offboarding and who may act for whom.
Browse by concept instead
Each pattern belongs to one or more concepts. If you arrived with a term rather than a workflow, start there.
- Permission Fatigue
- AI Approval
- Policy Engine
- AI Spending
- MCP Security
- Agent Permissions
- Independent Execution Authority
- Execution Control
- AI Egress Control
- Policy as Code
- Execution Governance
- Agent Permission Scope
- Approval Evidence
- Pre-Execution Authorization
- Approval Bypass
- Checkout Validation
- Agent Refund Limits
- Merchant Controls for Agent Orders
