Three. The OS reacts
You set the authority boundary.
Observe, recommend, ask first, or act on its own inside rules you write. Everything outside that boundary goes to an approval area showing the exact action that would run, in fields you can edit.
Pending · shipwright build · filed by the quartermaster
feature Conflicts strip shows the reason a move was requested
budget $10.00 · cost ceiling, stops on overrun
target staging · CI · browser test · then a merge request for you
notes editable until approved
ApproveDenyEdit fields
Reaction is fast enough to be useful rather than historical. A nudge ten minutes before a meeting. A double booking flagged the first time it appears, once, not every cycle. Approve something on your phone and it leaves the tray on your desk before you look up.
Authority is a set of dials, not a single yes. Keys carry scopes and a room list. A connected computer starts with no capability tiers at all and gets only the ones you grant. A background worker carries a daily cost ceiling. Inside those bounds the system acts. Outside them it asks.
Every surface that wants a real-world effect calls one function that inserts a pending row holding the exact JSON payload that will fire, and journals a request packet. Nothing runs until a resolve function runs with approval, and you can edit the fields first. What is in the fields at approval is what runs.
Above the twenty-five-dollar PIN line, approving also asks for a PIN. It is a second factor layered on scope, so a leaked key can work the approval area but cannot spend.
If the executor throws, the action is marked failed with the error text and an interrupting card appears reading "Approved, but it did NOT execute." That card exists because three approved ships once failed silently. The same lesson is a written line in the resident agent's doctrine: never report an action you did not see succeed.
Where the boundary sits by default
Waits for you: email sends, calendar moves, paid builds, the birth of a new worker, production merges, any shell, input or app action on your machines that an agent asked for, and destructive-looking shell commands no matter who asked.
Runs inside the boundary: opening a pull request, sending a text, blocking time on your own calendar, adding a task, generating an image, and a build under twenty dollars from a key that carries execute scope.
How the dials are set
Access keys come in four profiles: observer (read), operator (read, approve, memory and write), executor (adds execute and connector), and owner (everything, including minting keys). Each key also carries a rooms list and a tool profile, and a whoami call returns exactly what that key may call.
Machines are default deny on both ends. A fresh one has no tiers and no readable roots; you grant observe, shell, app or input, and the daemon re-checks the tier and a local path policy itself, so a wrong or compromised instruction cannot make the machine do what it was never granted.
Background workers are metered rather than trusted. A gateway holds the API key, compares the day's spend to the worker's budget, fifty cents by default, and returns 429 when it is spent. A budget is a cost ceiling, not authority: it pays for model calls and approves nothing.