How do we govern agents that take actions, not just answer?
What a process is technically able to do and what it has been permitted to do are separate questions, and automation causes harm precisely where they are treated as one. Nobody approves the action; the capability simply exists and gets exercised.
Audiences and roles bound what any process in Centralpoint can reach, and Data Triggers make the conditions for automated action explicit rather than implicit in code. Actions are recorded alongside the AI activity that prompted them, so behaviour is reviewable against the authority granted rather than against an impression of reasonableness after the fact.