AgentOS

Product

Eligible task categories can complete without final review under a setting you choose.

Review proposals. Configure eligible task categories. Inspect the available change records.

  • act_with_approval currently follows the same task path as recommend. Do not treat four named modes as four distinct operations.
  • Autonomous task completion is not publication, and it does not write a policy UUID.
  • After 10 consecutive recorded approvals and opt-in, approving an eligible non-voice Inbox proposal also commits it.
  • Draft by default in this publish flow; direct publication requires a connection opt-in.

See the separate controls on /security

Behavior by agent and category

Rendered from the accepted D9 table. Components do not paraphrase these rows.

Accepted D9 behavior table
AgentAction categoryDefault (E / T / P)Operator changeControlled inLogged fields
SEO Specialist (Carl pipeline)Read/analyze connected search data; prepare audit/recommendation workE/T/P catalog-included. Read/analyze and queue capabilities exist; these are not publication or an approval-required read. Task work entering implementation_tasks follows R. [A1][A4][A20]Per-client/category autonomy affects the task pipeline, not all chat/read tools. Actual connected properties and grants NV.Agent detail -> Permissions & Autonomy; client selection and category rows. Separate data connections. [A3][A21]Task dispatch/completion: L1/L2 when those branches run. No per-read business audit completeness asserted.
AI-Visibility Specialist (Carl pipeline)AEO findings, recommendations and task workE/T/P catalog-included. R for this pipeline; not a distinct global AI-Visibility permission dial. [A1][A2][A4]Same tuple-scoped controls; no separate role-wide policy is inferred from a display name.Same Agent detail control; actual category strings come from task history/settings. [A3]L1/L2; originating agent defaults to carl when absent in the inspected task paths. [A4][A5]
Content Strategist / content work (Carl pipeline)Draft/implementation work, before external publicationE not catalog-included; T/P included. R wherever the task path is used. Agent-owned work may execute to produce a deliverable before final review; human-owned dispatch creates an approval record. [A1][A4][A6]Observe / Recommend / Act with approval / Autonomous per tuple, subject to section 3 exclusions. Does not turn on an external publisher.Agent detail plus content workspace. [A3][A21]L1/L2/L3 as applicable; no guaranteed content diff for every task.
SEO / AI-Visibility / Content task originatorobserve task dispatchE/T/P eligible task paths: not default; configured observe cancels dispatch with autonomy_observe_no_action, before owner-type dispatch; already-created task remains. Not no-data-processing or a global agent pause. [A4]Yes, unless category is locked; observe does not govern unrelated APIs/jobs.Same tuple control. [A3]L1, agent actor, diff.autonomyLevel, category, reason; task dispatch_state, dispatch_error.
SEO / AI-Visibility / Content task originatorautonomous final task completionE/T/P eligible paths: not default. All nonempty plan steps delivered to DONE/completed without final human review. Does not mean publishes the result to a client site. [A5]Yes per tuple; no mandatory history threshold in PATCH. No verified policy UUID in completion log. [A2][A3]Same tuple control; UI promotion suggestion is advisory. [A21]L1 actor system:autonomy:<originating-agent>, type agent, action approve; L2. No human approver or policy-id field in this write. [A5]
Any task originator reaching plan-step deliveryDiagnostic serp_check, indexation_read, diagnostic_read with explicit review_policy=noneE/T/P: these exact task types can auto-complete under the separate no-review allowlist, even without an autonomous setting. Missing review_policy=none does not enable this path. [A5][A7]Not a general operator-configurable category list; allowlist is code.No general UI control established for setting this payload; NV.L2 state history. Dedicated autonomy L1 branch is not run when the no-review gate already allows completion. [A5]
All configured task agent IDs, including internal Normanbilling*, contract*, agreement* category prefixesE/T/P: resolver forces R regardless of stored setting. This is a resolver exclusion, not proof every billing/contract operation always requires human approval. Contract module separately catalog-gated to T/P. [A2][A22]PATCH rejects any value other than recommend for these prefixes. No operator override here.Agent detail/API locked category. [A3]L1 on accepted setting updates; L2/L3 according to actual downstream route. Never infer a human decision from action=approve.
Paid Media Analyst (Carl)paid / paid_* implementation recommendationsE/T/P included. Default R. Stored autonomous resolves to act_with_approval; PATCH rejects autonomous. Agent-owned paid tasks skip agent-task execution queue and remain pending for Paid recommendations/MutationComposer. [A2][A4][A8]Observe/recommend/act_with_approval; autonomous unavailable through this API.General Agent detail + Paid recommendations. This control is separate from Ads mutations and ladder.L1 for observe/settings; task fields L2. Mutation receipts do not follow merely from a recommendation row.
Paid Media Analyst (Carl)Prepare Google Ads mutationE/T/P catalog-included. Explicit prepare builds operation, applies guardrails and Google validate_only, then stores validated ledger row. Dry-run is not live application. Chat tool prepares; HTTP routes additionally allow scoped agent callers. [A9][A10][A20]Client guardrails and connection; human UI or agent API with client.read + ads.write. This is not the R8 dial.Paid MutationComposer / mutations; separate Ads connection and guardrails. [A9]L4 requested_by, requested_by_type, nullable approved_by, before/after, validation time. approved_by on agent prepare may be caller-supplied; not independent proof.
Paid Media Analyst / permitted Ads API actorExplicit commit/revert: all ten supported mutation typesE/T/P: validated mutation needs a commit request unless the eligible ladder path below commits it. Revert prepares an inverse for the same commit gate. US: human-only execution invariant; commit route allows ads.write agent callers and commit service does not require a persisted human approval. [A9][A10]Human operator can commit; scoped agent API is also implemented. Runtime grants NV.Paid mutations/history; API.L4 plus L1 on successful commit path, before/after/status; verified_at only if verification succeeds. Committed is not verified. [A10]
Paid Media AnalystLadder eligible: add_negative_keywords, negative_list, bid_modifierE/T/P: counter 0, opt-in false. At least 10 consecutive recorded approvals plus explicit opt-in, non-voice, current single-mutation Inbox Approve then immediate commit; skips a second commit click, not the current approval click. [A11][A12]Opt-in per tenant/client/mutation type, not per agent. Reject/edit resets counter; auto-applied rejection/revert can revoke opt-in. Threshold check also precedes opt-out; disable-any-time not established.Paid Settings -> Ads autonomy ladder. UI/API details in [A13].L4; L1 agent actor system:autonomy:<mutation-type>; ladder counters/times L5. Opt-in setter logs to logger, no independently attributed human audit row established.
Paid Media AnalystLadder excluded: budget_update, campaign_status, update_rsa, add_keywords, keyword_bid, campaign_settings; also non-allowlisted keyword_statusE/T/P: no ladder auto-apply. keyword_status is supported by mutation API but is not eligible, even though omitted from named NEVER list. Money/ad-copy always-human is not proven because the separate commit API permits scoped agents. [A9][A11]Cannot enable these through ladder setter. Agent API scope is a separate permission boundary, not an exception licensed by this table.Paid mutation commit controls; scope grants.L4/L1, not proof of a human sign-off.
SEO / AI-Visibility / Content publication (connection, not a persona dial)WordPress/Shopify content publicationE not catalog-included as Content; T/P included. Route request defaults to draft; direct publish needs per-connection allowDirectPublish, verified/enabled connection and credentials. Route accepts content.write agents as well as sessions; no universal per-item human approval check in the reviewed publish handler. [A14][A15]Per-connection direct-publish opt-in, disable; global disable supported. Does not follow automatically from task DONE. Actual adapter/connection configuration NV.Client publishing connections / content publish controls, separate from R8.L6 attempt receipt plus L1 route audit. Draft may write externally without making content public. Result state, not button label, determines claim.
SEO / AI-Visibility / Content publicationGitHub PR publishing adapterE/T/P same connection boundary above, not a new tier promise. Adapter returns proposed with review URL; opening a PR is not merge/deploy/publication. [A16]Destination/repository review remains separate; this review authorizes no merge.Publishing connection -> GitHub PR review.L6 result_state=proposed, review_url, external reference. No production-change guarantee.
SDR / Pipeline Assistant (Wesley)Pipeline/contact reads and outreach draft preparationE not catalog-included; T/P included. Tool manifest exposes reads and Inbox draft preparation, not an external send tool. This is not evidence that all CRM writes obey R8. [A1][A20]Operator reviews drafts. No global four-level control for outreach established.CRM/Inbox. Drafts scoped to tenant/contact; not necessarily client. [A17]Approval/draft records; no promise every read has L1.
SDR / Pipeline Assistant (Wesley)Approve outreach draft / sendE not catalog-included; T/P included. Inbox approve calls activity stub: stores email_sent activity, marks draft sent/follow-up done; no external Gmail send in this function. US: email-delivered footage/copy. [A17]Human Inbox interaction, not an automatic external send policy.Inbox outreach card.Activity occurred_at, proposed_by_agent_id, created_by_user_id; event payload sendMode=activity_stub; not delivery evidence. [A17]
Account Manager (Ben)Coordination / intervention actionE not catalog-included; T/P included. Chat capability map has no tools for Ben; Inbox intervention action marks ACTIONED/DISMISSED/READ and separately handles Ads-linked items. Not proof of general autonomous Account Manager execution. [A1][A12][A20]Human Inbox actions; no claim the R8 settings create a Ben executor. Ben is absent from task execution target allowlist. [A7]Inbox interventions; agent detail may store Ben settings without establishing executable capabilities.Intervention update attribution as passed by caller; Ads-linked paths L4/L5. Completeness NV. [A12]
Internal engineer Norman / Partner custom rolesInternal execution or custom capabilitiesNorman is an internal task target, not an extra marketed specialist. Partner custom catalog entry is not evidence of a shipped custom-agent execution/policy contract. E/T/P: no additional marketable behavior verified. [A1][A7]Internal settings/grants do not authorize marketing additional roles.Internal scope/target configuration; custom UI/runtime NV.Only the applicable task/API records; no additional logging guarantee.

Two controls, not one slider

Task autonomy is a per-client, per-agent, per-category setting. Google Ads mutations use a separate ladder. There is no generic 0-3 dial on this page.

Workspace screenshot, dark
AgentOS workspace used as a stand-in until a dedicated autonomy screenshot ships