“Where can an agent act, and where must it not?”
An agent can only act on what is explicit. Cross the AI lens with sensitivity and workflows and you get a defensible order of automation — safe, well-mapped steps first, restricted ground fenced off.
Repetitive, low-sensitivity steps ready to delegate — and restricted or Tier-1 steps that must keep a human in the loop.
A phased automation plan with guardrails drawn from real classifications, not guesses.
Take account provisioning. The create-ticket and notify-manager steps are low-sensitivity and repetitive, safe to automate. The grant-access-to-restricted-systems step is Tier-1 and highly classified, so it keeps a human approver. The model draws that line for you.