Tutorials › Agentic AI › AI Agents in Production

Agentic AI · Part 7 of 7

AI Agents in Production

Running agents in production: authorization, confirmation, auditing, limits, and sandboxing.

The loop in The Agent Loop runs any tool the model requests. What has to surround it before it's safe to point at production is authorization, confirmation, auditing, limits, and sandboxing.

The loop and its authorization step

flowchart TD
  A[User request] --> B[Model reasoning]
  B --> C[Tool selection]
  C --> D{Authorization}
  D -- allowed --> E[Execution]
  D -- denied --> B
  E --> F[Observation]
  F --> B
  B --> G[Result]
  

Every box in that loop except authorization is the model or plumbing that carries its output along. Authorization is the one box that must not be the model. A model can request that an action happen; whether it's allowed to happen is a decision made by code outside the model, using rules the model doesn't get to set or override. A model approving its own request is not authorization.

The prompt asks; code decides. Instructing a model in its system prompt not to delete production data, or not to send an email without confirmation, is a request the model can misread, be talked out of by a cleverly worded input, or generalize incorrectly under an unusual case it wasn't trained on. A rule enforced by code that runs regardless of what the model outputs has none of those failure modes: it either allows the action or it doesn't, independent of how convincingly the model has argued for it.

Designing the authorization boundary

A few concrete practices make that boundary enforceable:

All seven practices hold regardless of which orchestration framework or which model is in use. They're the same authorization boundary Identity and Access Management covers for human and service accounts, applied to a caller whose next request nobody can know in advance, because a model is the one deciding what to ask for.

Try it yourself

The Colab notebook builds each part of this series around a small open model, in the same order: the loop, structured tool calling, planning, memory, and a small team of agents you can chat with. It then rebuilds the same team in LangGraph.

Practice in Colab →

This site's Roundtable project is the same supervisor-and-specialists pattern running as a live app.

See it live: Roundtable →