Your agent is about to hold a credential to a system that holds someone's record.
For agentic AI
Agents make more decisions.
Their evidence needs to be just as specific.
Record the model, tools, permissions, purpose and human oversight relevant to an agentic workflow, then show which claims are actually supported by evidence. A Droplet records the accountable decision for one context; AffectLog does not control the agent at runtime.
An agent does not answer. It acts.
A chatbot produces text a human reads. An agent calls tools, holds credentials, writes to systems, and produces effects nobody sees individually - in a triage queue, a claims file, or a minor's account. Scan the system, issue the passport, grant the visa: the visa is where the consequence of acting is bounded.
Four live failure modes
Agents already in production - with no visa.
A clinical assistant that can write to the patient record, with no oversight gate and no event log.
With a Droplet
The Droplet records a read-only clearance in one context. Every write is named as an act that requires a named clinician under AI Act Art. 14, and the Art. 12 logging the deployment must keep is declared against the grant.
A claims-handling agent retrieving from a corpus that anyone can add a document to.
With a Droplet
The corpus is untrusted input. The visa records it as such, and the DPO and CISO clear how it is handled before the grant - an injected instruction would otherwise inherit the agent's full data access.
An MCP-enabled agent selecting whichever tool it judges relevant, with no declared list.
With a Droplet
The tool allowlist is declared at grant and cleared by the CISO. A call outside it is outside the clearance on record. An agent with no declared tools has no boundary to review.
An eligibility agent scoring applicants on a model swapped out two quarters ago.
With a Droplet
A model or provider change is a reason to re-review: record it, and the passport's Art. 15 accuracy and Art. 10 bias evidence is reviewed again before any Droplet granted on it is renewed. Under GDPR Art. 22 the decision must remain contestable; on unreviewed evidence, it is not.
The controls
Four things a visa fixes that a passport cannot.
One context
Cleared for THIS deployment, on THIS data, for THIS population. A second context requires a second visa.
Tool allowlist
Every callable tool declared at grant. Anything else is outside the clearance on record.
Art. 12 event log
The logging the deployment must keep, declared at grant: tool, timestamp, context, action, approval.
Expiry and renewal
Expires by default. Renewal is a new decision. A model or provider change is a reason to re-review before renewal.
Human oversight - AI Act Art. 14
The acts that require a named human.
Art. 14 requires oversight that is effective: a person able to interpret the output, disregard it, and intervene. A Droplet names which acts require a human, who that human is, and what record the intervention should produce. An approve button with nothing behind it is not oversight.
Visa lifecycle
Grant. Gate. Log. Renew.
Grant
Against an issued Ripple only. One context, one data scope, one tool allowlist, one expiry.
Gate
DPO clears the data scope. CISO clears tools, credentials, and egress. Under seal where consequence is highest.
Log
Grant, review and renewal decisions are logged with actor, role and time in a hash-linked audit log.
Renew
Expires by default. Renewal is a new decision against the passport's current evidence - or a recorded refusal.
The difference
Agents in production - with and without a visa.
Without a Droplet
- Cleared once, everywhere - the context was never named
- Tool selection left to the model at runtime
- Tool-calls unlogged - the act cannot be reconstructed
- The RAG corpus trusted as content, not treated as instruction
- Oversight is an approve button with no basis to disagree
- No expiry, and no way to stop the agent without shipping code
With a Droplet
- One visa per context - a new population needs a new grant
- Tool allowlist declared at grant and cleared by the CISO
- Art. 12 logging obligations declared against the grant
- Corpus declared as untrusted input before the grant
- Art. 14 acts named, with the human who can override
- Expires by default; renewal requires a new decision
Addressed
Agent governance - the four objections we hear.
“The agent already has a Ripple. Why grant a Droplet as well?”
A passport says what a system is. A visa says where it may operate. An assistant passported for adult emergency intake holds no clearance for paediatric intake - the population changed, so the evidence no longer covers the deployment. The passport is untouched; the visa must be granted afresh, or refused.
“Our agents are internal tools, not vendor products.”
Internal agents typically hold more access, not less: production credentials, patient and customer records, write paths into core systems. And there is no procurement counterparty forcing the evidence. A Droplet restores the gate that the absence of a purchase order removed.
“It is a prototype. Governance can wait until production.”
A prototype with a live credential is a production agent with no owner. If it wrote to a clinical record last Tuesday and the calls were not logged, no governance added afterwards can reconstruct what it did.
“We already monitor agents with an observability stack.”
Observability records what happened. A visa states what was authorised, in which context, under which conditions, until when - and lapses unless someone decides to renew it: a decision before the next act rather than analysis after it. Under Art. 12 the log is necessary. Under Art. 14 it is nowhere near sufficient.
Step 3 - the visa
Grant the visa
before the agent acts.
One context. One data scope. One tool allowlist. One expiry date. Nothing else stands between a passported agent and an act nobody cleared.
AffectLog provides technical and operational evidence to support AI access, supplier-risk, security, privacy, and governance review. Not legal advice, certification, notified-body conformity assessment, or regulatory approval.