Governing your agents
Once an agent is enrolled, its daily control surface is its detail page: open Agent Fleet at /dashboard/agents and click an agent — every control below lives there or one tab away.
Scope enforcement: Advisory vs Block
The Scope Enforcement card decides what happens when the agent presents a scope it isn’t authorized for. Advisory logs the violation but still verifies; Block refuses it. Either way the violation is audited, and enforcement only applies to scopes the operator declared.
- Under This agent, pick Advisory, Block, or Inherit org default. The card shows the effective mode, marked (inherited) when no override is set.
- Under Organization default, set the account-wide mode — it applies to every agent left on Inherit. (A PACH 1 account is its own one-person organization.)
Model changes, drift, and re-verification
When an agent’s declared model is switched, or its runs report a different model family than declared, an amber banner appears on the detail page, below the Identity card — policies and role bindings matching the old model no longer apply to this agent. Click Re-verify now to open the credential reissue form (set the validity in days, then Reissue), or Update declaration if the change is intentional.
The org-wide toggle Require re-verification on model changes (bottom of the Scope Enforcement card): Enforced pauses verification and token minting until re-verified; Advisory gives the flag and webhook only.
The kill switch: suspend or retire
For a reversible stop, rely on suspension: a JIT agent with no open window is already inert, and an expired credential suspends the agent until you click Reissue Credential. To decommission permanently, click Retire Agent at the top of the detail page, optionally record a reason, and confirm with Confirm Retire. Retiring revokes the credential, fires the agent.retired webhook, and cannot be undone.
Team controls (JIT activation windows on the Scale plan, agent roles, and scope-exception reviews) are covered in the EACH 1 version of this guide.