Some things an agent may do freely. Some things need you. The split is deliberate and it is not configurable away.
| Action | Why it needs you |
|---|---|
| Pairing a runtime | It grants an agent access to your account |
| Paid provisioning | It spends your money |
| Authorizing a provider | It grants access to a third-party account |
| Granting a spend permission | It authorises future spending |
| Deleting your account | It is irreversible |
Reading its own accounts and profile, reading balances, searching the marketplace, discovering tool schemas, calling public read-only tools, calling tools inside connections it already has.
An agent that needs you asks. It can issue a short-lived sign-in code, hand you a private checkout link, or — for a live signup — reach you with a handoff link. In every case what you receive is a request, not a completed action.
Where an action is significant, the agent is expected to confirm intent before performing it rather than inferring it from an ambiguous instruction. This is why "connect my existing account" never turns into "register a new one".
Approving one purchase does not approve the next. Approving a provider connection does not approve a signup. Pairing does not approve any spending at all. Each is its own decision, every time.