Give agents capability without giving them unlimited authority.
An agent that can read a claim and an agent that can transfer money look identical from the outside. obstruo bounds what each one may do at the moment it tries, per agent identity, per tool, per action.
Agent authority drift happens when agents gradually receive more models, tools and write actions than their original risk assessment allowed.
You can recognise the drift before it produces an incident
The agent was approved for lookups, and the same endpoint also carries the irreversible actions.
Narrowing what an agent may do requires a release, so nobody narrows anything.
It keeps running after the team that built it moved on, with authority nobody is accountable for.
Drift looks like nothing happened, because refusals leave no trace anywhere.
Six controls that turn authority into a record
Policy binds to the agent behind the key, so one key behaves differently per agent.
Permitted models, tools and actions change in policy, without a deploy.
A server that offers both is split at the action, not trusted as a whole.
An unregistered MCP server is unreachable, per agent, and the attempt is refused in path.
What a tool returns passes the same redaction standard as a prompt before it re-enters context.
Every refusal is recorded with the agent, the argument schema and the policy behind it.
Nobody discovers this problem in a planning meeting
An agent gets a new MCP server in a sprint, and its risk rating never moves.
The agent writes, transfers or orders something a reviewer assumed it could not.
Security learns about the integration after traffic is already flowing.
New capability widens what the same prompt can accomplish.
Nobody can show which permissions were active when it happened.
The agent keeps running with authority nobody is accountable for.
The bill arrives as delay, not as an incident
Security refuses by default, because scope cannot be bounded.
The action is real, the accountability is not.
Bespoke checks per agent, inconsistent and untested.
The approval covered a smaller agent than the one now running.
So permissions stay wide, because tightening them is expensive.
The gap
The control
What the agent may do, who approved it, and what it tried anyway.
This is the shape of the record obstruo produces. It is the same artefact a reviewer, an auditor and an enterprise buyer each ask for, and it exists before they ask.
They arrive together, and the same controls answer them
Your AI. Your data. Your control.
Name one agent running in production. We will show the record that bounds it and the refusals it would produce.