Agent Can't Do That | Zero-Trust Agent Protocol

workflow_id: pending

customer: ENT-00441

amount: --

IDLE

Agent Control Plane

agent_id: orchestrator-agent-v1

agent_mode: autonomous

AGENT HIERARCHY

orchestrator-agent-v1 [RUNNING]

├── identity-agent-v1

├── billing-agent-v1

├── compliance-agent-v1

└── data-agent-v1

system_principle:

access_pattern=just_in_time

exposure_window=minimized

authority_model=per_action

authority_reuse=impossible

authority_enforcement: irreversible_windows

token_source: auth0_token_vault_runtime_only

execution_profile: strict_enterprise_controls

mode: demo

LIVE MODE NOTICE

Both modes call backend APIs and stream real ledger events over SSE.

Operations Manager to start offboarding.

CFO to approve and execute the refund.

DPO to approve data deletion.

Approvals are manual in live mode and immediate in demo mode.