What an agent is
An agent is knowledge plus a toolbox, set on a recurring stream of work. The weekly overview. Inbox triage. Meeting preparation. The signals you want to see.
It knows your organisation from the same knowledge base that the AI tools of your people read: universal AI context. It reaches your systems through connections: mail, calendar, documents, numbers, dashboards. And it can only take the actions you gave it.
You ask it in your own AI tool, and it answers there by name. That tool reaches Dienox through MCP, the open standard for connecting AI tools to data and systems.
Every action has a level
Every action on every connection is read, write or irreversible.
| Level | What it covers | Examples | Does it wait for a person | When it is switched off |
|---|---|---|---|---|
| Read | Looking without changing anything | Revenue and orders, the calendar, a contract | No | The action is not in the toolbox. The agent cannot look |
| Write | Creating or changing something | A report, a draft reply, an answer in a ticket | No | The action is not in the toolbox. The agent cannot write it |
| Irreversible | What cannot be taken back | Mailing the board, closing a ticket, making a payment | Yes, for someone with the right role | The action is not in the toolbox. There is nothing to approve |
You switch each action on or off, per agent. Take an agent that prepares meetings. It may read the calendar, past decisions and the numbers. It may not change the invite. For that agent, that action does not exist.
The same holds on every layer of an organisation. A weekly overview for leadership reads revenue, orders and project status, and writes the overview. Mailing it to the board waits for a person. An agent that watches for signals reads dashboards and contracts, and tells the owner when something is off. Restarting a service is switched off. It does not exist for that agent.
Cannot, rather than will not
Reading numbers: yes. Making a payment: no. Not because the agent is asked nicely, but because the option technically does not exist.
A rule in a prompt is a request. "Do not make payments" asks a model to behave, and usually it does. That is "will not". It holds until a question is phrased the wrong way, or a task is misread.
Dienox works the other way. An action that is off is not in the agent's toolbox. It cannot be called, however the agent is asked. There is nothing to talk it into, because the option is not there.
"Cannot" is stronger than "will not", and it is the only thing we promise.
Human-in-the-loop, and why it is not enough on its own
Human-in-the-loop means a person approves before the agent acts. It is the control most people think of first. Where an action matters, it is the right one.
It is not enough on its own. A person who approves forty things a day stops reading them. The approval is still given. It no longer means anything.
So the order matters. The first control is what an agent can do at all: what is off does not exist for it. Approval comes second, and only for what cannot be taken back. That leaves few questions, and each one is worth reading. The glossary has the short version.
A person approves where it matters
An irreversible action waits for someone with the right role, in Dienox. Until someone signs off, it does not happen. The glossary defines sign-off, permission levels and toolboxes in a few sentences each.
An approval counts once. It covers that one action, not the next one like it. The next time, the agent asks again.
Roles decide who may change what: administrator, editor or reader, per organisation. A connection works under the role of whoever connected it, and it belongs to one organisation. Nothing crosses from one organisation to another.
Every action leaves a trail
What was read and what was changed, by which agent, for whom and at what cost. The agent answers by name, in your own AI tool, so you always know who is talking. Every change to your knowledge can be undone.
Its way of working is written down as well, for you to read and change.
For a small organisation
A small business rarely has a security team, and it does not need one for this. Three habits are enough.
- Switch on only what the work needs. Per agent, per action. The rest does not exist for that agent.
- Start with read. An agent that only reads changes nothing.
- Let one person approve. Give the role to someone who knows the work. Irreversible actions wait for them.
Start with one
You switch on one agent at a time. Each one earns its place before the next joins. A good first agent reads a lot and writes little: a weekly overview from the systems themselves, or every standing meeting prepared with the numbers that belong to it.
The home page lists every control in its security section: permissions per action, approvals, the trail, roles, where it runs, and why your knowledge stays yours.
Questions people ask
What does human-in-the-loop mean for an AI agent?
Human-in-the-loop means a person approves an action before the agent takes it. In Dienox that is how irreversible actions work: mailing the board or making a payment waits for someone with the right role. Until that person signs off, it does not happen. Reading and writing do not wait, so the questions stay few.
Is human approval enough to make an agent safe?
Not on its own. Someone who approves forty things a day stops reading them. So the first limit is what the agent can do at all: an action that is switched off is not in its toolbox and cannot be called. Approval is for what remains and cannot be taken back.
Which actions should wait for a person?
The ones that cannot be taken back: mailing the board, closing a ticket, making a payment. Reading does not need approval, because it changes nothing. Writing a draft or a report does not either, because it can still be changed afterwards. If an action worries you, switch it off for that agent.
Can an agent be talked into something it was not given?
No. A rule in a prompt asks a model to behave, and a question phrased the wrong way can get past it. In Dienox an action that is off is not in the agent's toolbox. It cannot be called, however the agent is asked. There is nothing to talk it into, because the option is not there.
Who can approve an action?
Someone with the right role in the organisation. Roles in Dienox are administrator, editor and reader, and a person has a role per organisation. An irreversible action waits in Dienox for a person with the right role. Until that person signs off, it does not happen. Nothing crosses from one organisation to another.
Does one approval cover the next time?
No. An approval counts once. It covers that one action, not the next one like it. When the agent wants to do the same thing again, it asks again. That keeps every approval a decision about one concrete action, and not a permission that grows without anyone noticing.
What is recorded about what an agent did?
Every action leaves a trail: what was read and what was changed, by which agent, for whom and at what cost. The agent answers by name, so you always know who is talking. Every change to your knowledge is kept in its history, with who made it and when, and can be undone.
Is this suited to a small organisation?
Yes. It takes no security team. You switch actions on per agent, start with an agent that only reads, and give one person the role that approves irreversible actions. The Self-serve edition runs in the Dienox cloud and is ready the same day. You switch on one agent at a time.