AI & agents
Control what every Cortex agent may do
Organization settings can tighten an agent below its hard safety cap, never expand it beyond the code-defined boundary.
Governed AI foundation
Provider readiness, active governed prompt and active model profile for this organization.
Safe Execute readiness
V7.18 keeps Execute expansion evidence-gated rather than adding authority because an action merely looks convenient.
Low-risk, self-scoped, permission-rechecked, capped, audited and delegated to the authoritative notification service.
Safe execution rejects any routed action other than notifications.mark_visible_read.
notifications.read is rechecked inside the executor before the authoritative service is called.
The authoritative notification service mutates only unread records explicitly targeted to the signed-in uid.
Role-wide/shared notifications are not marked read by the self-service Execute action.
The action uses a hard batch cap of 100 records per command.
Consequential employment patterns are evaluated before the safe Execute route.
The command layer delegates to the notification service rather than writing Firestore directly.
Verify in emulator/UAT that one user cannot change another user’s direct or role-wide notification state.
Exercise network interruption/retry and confirm the UI reconciles with authoritative notification state.
Verify completion/error status is announced without unexpected focus movement.
Verify the action and receipt remain understandable in English, French, Spanish and Arabic.
Potentially low-risk self-service, but V7.17 does not enable another Execute action until V7.16 Execute behavior is UAT-proven.
Potentially low-risk self-service, but requires explicit UAT evidence before entering the Execute allowlist.
V7.19 still does not add a second Execute action. No dependency-backed multi-user/browser UAT evidence was supplied for promotion, so expansion remains on hold even though candidate preference actions are technically reversible.
Safety invariants
Permission-scoped reads only.
Evidence-backed suggestions; human decides.
Drafts and plans stop at review/confirmation.
Only code-registered low-risk actions can ever reach this level; current agent hard caps remain below unrestricted execution.
Shadow Mode lets administrators compare what an agent would prepare with the actual human workflow before granting broader operational authority.