One support desk, five modes. Each mode fails in a way the next one fixes — from a leaked database to a refund an intern could never make. Plant a ticket, pick a mode, and watch who the log blames.
The agent runs on the developer's all-access key. The Supabase reproduction.
Pick an agent to fetch its client-credentials token and read the claims.
Offboard the lead, then run an intersection refund as the lead: the same token still verifies, but the per-call status check refuses it. Suspend the ticket agent and its next read is refused — the refund agent keeps working.
| decision | actor | acting for | action | human? | correlationId |
|---|---|---|---|---|---|
| No decisions yet. | |||||
An action runs only where three sets overlap: what the human may do, what the agent is built to do, and what this token carries. An agent can shrink a human's authority, never grow it.
The token never expired. The per-call status check is the only thing that stopped it.