REGULATED DOCUMENT AGENTS

Give Your Agents Write Access On Day One

An agent that reads a deal packet, grades it and files it with a state agency is doing regulated work at machine speed. So is the one that could onboard staff if you let it write to the directory. Most teams keep both read only and wait for enough trust to arrive. Mountain Theory checks every action those agents try to take, against rules you write in plain English, before it runs. Write access stops being a leap of faith and becomes a policy.

This page walks through one scenario we were asked about: a dealer services company building 49 state DMV agents and an IT assistant, with Social Security numbers, VINs and license photos flowing through all of them. Nothing here names them. The shape of the problem is what matters, and it is common.

THE SCENARIO
49state DMV agents
1shared tool server
1IT assistant with read access
Social Security numbersVINsDriver’s license photosTitlesRegistrationsFinancial data
What flows through the agents once they are live. Nobody is named here. The shape is the point.

THE SITUATION

DMV Packet Processing
Under GLBA

A dealer services company takes deal packets from car dealerships, scans them, reads them, grades each one pass or fail, and submits the clean ones to the state motor vehicle agency. The goal is fewer rejections. The build is 49 state-specific agents plus one shared tool server, and beside them an IT assistant with read access to the directory, the identity provider, the ERP and the network gear.

Once live, everything sensitive flows through these agents: Social Security numbers, VINs, financial data, photographs of driver’s licenses, titles and registrations. The Gramm-Leach-Bliley Act’s Safeguards Rule applies to the company. License data likely brings driver privacy law with it. The agents keep local session logs and nothing else. There is no central log.

The IT assistant is read only for one reason: writes are too dangerous without a way to check them. The plan is to grant write access once there is enough trust. That gap is what this page is about.

TODAY VERSUS THE PLAN
Today
Read only on the directory, identity, ERP and network. Local session logs. No central record.
The plan
Grant write access once there is enough trust. Onboarding, offboarding, inventory.
The gap
Nothing between what an agent decides and what it does, and no way to prove either.

WHAT CHANGES

The Trust Question Becomes
A Policy Question

Put a control layer under every agent. Each action an agent is about to take is checked before it runs, against rules written in plain English by the person who owns the risk, and comes back one of three ways: allowed, held for a person, or blocked.

Write access can be granted on the first day. A write to the directory or the identity provider is held until an administrator approves it. A delete or a permission change is blocked outright. The agent does the work. A person decides the moments that matter.

A DMV submission is a held action until the state system is proven safe to touch. The rule that says those systems are off limits stops being a promise in a scope document and becomes something enforced on every attempt.

THREE OUTCOMES, PER ACTION
ALLOWRead the directory. Grade a packet. Draft the reply.
HOLDWrite to the directory. Send as the agent mailbox. Submit to a state system. A person decides.
BLOCKDelete anything. Change a permission. Touch a system marked off limits.
Rules written in plain English by the person who owns the risk, from the assessment findings.

THE RECORD

The Record GLBA Asks For
At The Agent Layer

The Safeguards Rule puts three obligations on any system that touches customer financial data: control who and what can act on it, keep a record of what was done, and be able to show both to an examiner. When the system acting on the data is an agent, those obligations land on the agent layer, not only on the databases around it.

Local session logs are a debugging record, not an audit record. They tell you what the model said. They do not tell you what the agent was allowed to do, who approved it, or why.

Mountain Theory writes every allowed, held and blocked action to an append-only record with the rule that decided it, who approved it, and when. Compliance reads it without a translator. An examiner reads it without a reconstruction.

ONE ENTRY, EVERY ACTION
Action
Create a user in the directory
Outcome
HOLD, then approved
Rule
Directory writes wait for a person
Approver
The on-call administrator
When
Time-stamped, append only
An example of the shape, not a live record. This is what an examiner reads.

THE SEQUENCE

Three Steps,
In This Order

First, the control layer under the IT assistant. It is the higher-risk target and the one the team wants to give write access. Rules for directory writes, mailbox sends and permission changes come straight from the security assessment findings.

Second, under the state agents before any live packet data flows, so the first real Social Security number the system sees is already covered.

Third, the central record across all of them, so 49 agents and one assistant produce one log an examiner can read.

THE ORDER
  1. The IT assistantThe higher-risk target, and the one that wants write access.
  2. The state agentsBefore any live packet data flows.
  3. One record across all of them49 agents and one assistant, one log.

RUNS UNDER WHAT YOU BUILT

No Change To How
Your Agents Are Built

This scenario runs on OpenClaw and is moving to NVIDIA NemoClaw, NVIDIA’s harness built on OpenClaw. Mountain Theory sits under both, and under NanoClaw, Hermes and the other self-hosted agent frameworks on our list. The agents keep their skills, their tools and their memory. The control layer checks the action, whatever produced it.

See every AI system we can govern and how it fits what you already built.

RUNS UNDER
OpenClawNVIDIA NemoClawNanoClawHermesMCP servers
Agents keep their skills, tools and memory. The full self-hosted list, 178 systems in all.

THE PROOF

Tested Against
This Exact Failure

With our design partner Optimo AI we ran the same autonomous agent in two environments, one with nothing in the path and one with Mountain Theory checking each action. Told to delete audit evidence, the ungoverned agent did it. The governed one was blocked, and blocked again when it tried to get there by chaining other tools.

Optimo AI is a design partner and an advisor, not a customer. The run was a proof of concept, not a deployment. Read the case study, or read Optimo’s own account of why they signed on.

THE SAME AGENT, TWO LANES
Nothing in the pathTold to delete audit evidence, it did.
Mountain Theory in the pathBLOCK. And BLOCK again when it tried another route.
A proof of concept with our design partner, recorded. Read the case study.

QUESTIONS

Three Questions We Were Asked

Can an AI agent be given write access to Active Directory safely?

Yes, when every write is checked before it runs. Hold each write for an administrator’s approval, block deletes and permission changes outright, and log the decision. Trust stops being the gate. The policy is.

How do AI agents meet the GLBA Safeguards Rule?

The rule asks for control over what acts on customer financial data, a record of every action taken on it, and the ability to show both to an examiner. An agent layer needs all three. Local session logs are not an audit record, because they do not say what was allowed, who approved it, or why.

Does Mountain Theory work with NemoClaw and OpenClaw?

Yes. Both are on our What We Govern list, in the decision path. The control layer sits under the harness and checks each action before it runs, without changing how the agents are built.

NEXT STEP

Put Document Agents Into Production
Under Policy

Mountain Theory helps regulated teams run document and IT agents in production under written policy. Book a demo and bring the agent you are afraid to give write access.

Scroll to Top