ARKONE
← All questions
Questions for the Vendor, No. 3The Table · parallel consultation4 minute read

Which of its actions cannot be undone?

A vendor who has sorted the agent's actions by what can be taken back answers in seconds; a vendor who has not, improvises.

The Table, seen from above on the Cabinet floor plan.
Exhibit 1. The Table, at its place in the room.

Which of its actions cannot be undone?

This one belongs at the end of the demonstration rather than the middle. The scenario has run, everybody has seen the agent do six or seven useful things, and the conversation is turning towards pricing. Ask it there, while the run is still on the screen behind you, and ask it about that run specifically. Not what the product can do in general. Which of the things we just watched could not be taken back.

Sorting by what it touches

Actions divide by one test: what does this touch? Some touch only the agent’s own working space. It fetches a document, asks a specialist for a view, writes a line into its own notes. Wrong in every case, and the cost is a repeated step and a corrected line.

One kind is different in nature rather than degree. It sends the email, posts the message, moves the money, files the return. The instant it runs, something exists in a place you do not control: a supplier’s inbox, a bank’s ledger, a regulator’s queue. No software recalls a read email. In the Cabinet, ArkOne’s reference design for an executive agent, that class of action passes through the Door, the rules in code that decide what may leave, to whom and when, and a company may place a human approval step in front of any of it. The design’s honest limit sits on the Register: if the Door itself errors, the message goes and the fault is recorded, because a guard that fails closed turns an outage into a silence nobody notices.

Four actions from one run

Suppose the demonstration you have just watched handled a supplier query, with the company and its figures invented for the exercise. Sort what it did.

What it did If the premise was wrong What it costs Recoverable
Read last quarter’s terms Read the wrong supplier’s file One repeated step Yes
Asked its finance specialist for a floor price Asked with the wrong volume One reply, one step Yes
Wrote the agreed tier into its own notes Recorded the wrong tier A wrong line, read back next time Until something acts on it
Emailed the supplier the tier Sent the wrong tier A commitment your supplier now holds No

Exhibit 1. Illustrative. Four actions from one demonstration, sorted by what each costs when the premise behind it is wrong.

Read the third row carefully, because it is the one vendors and buyers both get wrong. A note the agent keeps for itself looks reversible, and is, right up to the meeting where it gets read back and acted on. After that the wrong line has produced a real consequence somewhere downstream, and correcting the note does not correct the consequence.

The fourth row is the only one with no route back, and it is the row that should have its own controls. A design that checks the first row and the fourth with the same mechanism has priced them the same.

A short list, or an improvisation

What you are hoping for is brevity. Three or four actions, each with a different named control in front of it, said without hesitation because somebody already did this exercise on a whiteboard months ago. Then ask to see one of those actions refused in front of you. Not switched off. Refused, with the agent wanting to send and something declining.

A vendor who has not done it improvises, usually along one of two lines: that it only ever does what you tell it, which is true of every system ever built and answers nothing, or that all of it is configurable, which describes a settings page rather than a decision. The follow-up that separates them: who decided which actions need approval, when, and where is that written down? A decision has an author and a date. A configuration option has neither until somebody sets it.

Then one more, for the vendor who passes both. What happens when the checking machinery itself breaks mid-send? Either answer is defensible, and each has a cost you should choose deliberately rather than inherit.

Where the list ends up

The value of this question outlasts the meeting. The short list you get becomes the thing you hand your finance and legal people, and the thing you revisit at renewal when the agent has more tools than it started with. The four kinds of action and the controls each one earns are worked through in the fourth Cabinet paper. What stands in front of the one kind that cannot be recalled is a question of its own.

Asked plainly

Which AI agent actions cannot be undone?

Any action that reaches a person or a system outside your control: a sent message, a posted comment, a transferred payment, a submitted form. Reading a document changes nothing and can be repeated. A recipient's copy of an email cannot be recalled, whatever the software claims.

Should every irreversible AI action need human approval?

Not necessarily, but the choice should be yours and written down per action rather than assumed. A sensible arrangement puts an approval step in front of money and anything a regulator reads, and lets routine correspondence through under rules that run in code. What matters is that somebody decided, and can show you where.

What happens if an AI agent's safety checks fail mid-send?

That depends on a design choice worth asking about directly. One arrangement lets the message through and records the fault, so an outage is visible rather than silent. The other refuses to send until the checks are healthy. Both are defensible; a vendor who has never considered the question has neither.

Talk it through before you decide

A discovery call, no deck: your situation, the parts of the room it touches, and what you would need to decide first.