Understand the goal and plan
Select from visible capabilities and coordinate reads, writes, and multi-step work.
Cannot claim identity or expand its scopeBailingHub defines the most an agent may discover and request. The source system still decides whether this call is allowed under the current user, tenant, role, and live rules.
Security comes from separated responsibilities, not from hoping a model always behaves.
Select from visible capabilities and coordinate reads, writes, and multi-step work.
Cannot claim identity or expand its scopeCheck identity, route, risk, approval, idempotency, and invocation state, then record visible traces.
Cannot grant final business permissionRecheck user, tenant, role, field permission, and business state before execution.
Remains the final source of authority and recordA call must not only succeed; the system must explain why it was allowed, who approved it, and what finally happened.
Expose only operations intended for agents.
Establish a trusted subject from the business login.
Intersect client, route, identity, and policy.
Plan only with capabilities visible in this turn.
Check arguments, risk, approval, and idempotency.
Let the source system execute or reject under live rules.
Record visible steps, results, approvals, and errors.
Each mechanism solves a different problem. Allowlisting, approval, backend authorization, and audit are not one switch.
An agent cannot establish identity through a prompt. The business login and authorization flow confirm user, tenant, store, or other scope.
Configure business authorization and model plans separately; model allowance does not grant business permissions.The business side declares operations, the Hub projects a bounded set, and the backend may still reject a visible tool.
An Origin allowlist prevents unauthorized embedding; it is not server authentication.Routine authorized actions may run directly. Sensitive calls freeze tool and arguments, then resume only the approved invocation.
Approved calls must still pass final backend authorization.A timeout or audit-write error followed by a blind retry may duplicate a refund, record, or state transition.
The source system remains the final reconciliation record.Associate entry, identity, route, tool, approval, result, and error, then revoke an individual Agent Session when needed.
View sessions by device and revoke the corresponding Agent Sessions individually.Configure shared rate limits, job admission budgets, pause control, and metrics to manage traffic and detect problems in a self-hosted instance.
With MySQL, client, chat-entry IP, admin-login, tool-provider, and per-tool limits use a shared ledger instead of independent process-local windows.
Route and client budgets use recorded tokens or costs to reject new jobs at the limit. The model-plan gateway settles actual usage asynchronously without interrupting output for billing checks; concurrent requests and late settlement may exceed the allowance.
An administrator can activate the kill switch through the admin endpoint or a .paused file. Callers should fall back to a human queue instead of creating a retry storm.
Optional GET /metrics exposes queue pressure, executor liveness, approval waits, expired leases, and audit-write failures. It is disabled by default and requires a dedicated Bearer token.
Runtime guardrails can only tighten Hub risk. They never replace the source system’s final authorization of the current user, tenant, role, and business state.
Connect existing services, accounts, and permissions to give agents explicit business operation entry points.
BailingHub defines the most an agent may request. The business system decides whether this call is allowed now.
Calls explicitly declared server-side capabilities instead of clicking arbitrary pages.
Business data is returned through controlled APIs; the source system retains ownership.
Every entry, identity, and route should retain least privilege.
The SDK provides protocol methods while the business system implements the page for its login model.
Start with a low-risk query and one governed write, then verify identity, authorization, approval, outcome, and trace.