# What agents may do, and when to ask

Emboss publishes an agentic access contract: one document that labels every call an agent
can make on Emboss, on every surface: the REST API, the pay-per-call API, the MCP
connector's tools and the A2A agent's skills. Each label says what the call does, how
serious it is, how long a sign-in for it should last, whether a person should approve it
first, and whether it should be audited. Agent platforms and gateways read it to decide
when to stop and ask.

- JSON: [https://getemboss.ai/agentic-access.json](https://getemboss.ai/agentic-access.json)
- YAML: [https://getemboss.ai/agentic-access.yml](https://getemboss.ai/agentic-access.yml)

The labels use the `x-agentic-access` vocabulary (Curity's Access Intelligence model). The
same label sits on every operation in the [REST API description](https://api.getemboss.ai/internal/openapi.json)
and the [pay-per-call API description](https://api.getemboss.ai/openapi.json), in each MCP
tool's `_meta` under `ai.getemboss/agentic-access`, and the A2A agent card links the contract.

## When a person should approve

| Calls | Ask a person first? |
| --- | --- |
| Reads: list forms, job status, usage, finding a library form | Never |
| Free work: PDF page tools, reading a proposal, attachments | Never |
| Paid work: making a form fillable, fills, checks, read-backs, packages, pay-per-call charges | Never |
| Sending a fax | Only for a burst: more than 10 faxes from one account within an hour. A new fax number alone needs no approval. |
| Deleting a form | Always: it removes the form and its files for good. |
| Creating, changing or revoking an API key | Only a person can, on the website; agents have no call for it. |

Emboss itself holds no call for approval. The contract is guidance for the agent and the
platform running it; Emboss's own limits, such as those on fax volume, apply either way.

## What each label carries

- `action-class`: `connected` for a read, `acting` for a call that changes something.
- `consequence`: `read` or `write`.
- `subject`: `required` when the call acts for a named account; `optional` for
  pay-per-call and other public calls, which a payment or nothing authorises.
- `scope`: `forms:read` or `forms:write` on account calls.
- `token`: a connector's access token lasts 3600 seconds (an hour) and renews automatically;
  API keys last until revoked.
- `escalation`: present only on the calls that ask, above.
- `audit`: `required` on every call that changes something, so the platform running the
  agent keeps its own record.
- `x-billed`: on account calls, the kinds of charge the call can make. Pay-per-call calls
  are paid per call instead (`x-authorization: per-call-payment`).

## Deleting a form leaves a record

When a form is deleted, Emboss keeps a record of when, and whether it was deleted on the
website, through the API or through a connector, with the API key used if there was one.
The record holds no document content.

## See also

- [Send a fax from an agent](https://getemboss.ai/use-cases/send-a-fax-from-an-agent)
- [MCP server](https://getemboss.ai/glossary/mcp-server)
- [MCP tools reference](https://getemboss.ai/docs/mcp-tools)
- [MCP tools reference](https://getemboss.ai/docs/mcp-tools)
- [Use Emboss from agent frameworks (A2A)](https://getemboss.ai/docs/a2a)
- [Pay per call](https://getemboss.ai/docs/pay-per-call)
- [Send a fax](https://getemboss.ai/docs/send-fax)
- [Send a fax](https://getemboss.ai/docs/reference/fax)
