AGENTIC CAPABILITY 20 · AI COMMAND LAYER

Shutdown Authority

"any agent can be stopped — by name, at once"

HUMAN GATE REUSABLE PATTERN

Today, stopping a system means finding the right person — then a meeting.

When something behaves off-pattern, the path to halting it runs through whoever built it, whoever holds the licence, and a change window. Minutes of misbehaviour become hours of exposure. That was tolerable when nothing ran unattended; it isn't when agents work around the clock.

This is the capability that puts the stop in a named human's hand: a pre-authorised control that halts any agent — or the whole fleet — in one move, with the halt itself on the record. It is the human gate over your digital workforce, and it completes Agent Identity: the register gives every agent a name; Shutdown Authority is what the name is for.

What it does for your function

One pre-authorised move — a named owner stops any agent instantly. No ticket, no meeting, no hunt for whoever built it.

Scoped or total — halt one agent, one function's fleet, or everything on the register. The stop is as wide as the risk.

The stop is on the record — who halted what, when and why is logged. And so is the restart.

HOW IT STAYS BOUNDED

The stop is held by a person — never by another agent.

Shutdown is a human authority, granted in advance and instant in effect. No agent can trigger it, suppress it, delay it or work around it — and nothing restarts without a named owner's yes.

Where this pattern fits

Anywhere agents run in your name — the authority is one; what it covers grows with the fleet.

First deployment

Wave 1 ships with the stop in place before the first agent runs — not retrofitted after.

Incident response

Behaviour off-pattern: halt first, investigate second, restart deliberately — in that order.

Planned change

Policy updates, upgrades, model changes — a clean, logged halt and a deliberate restart.

Regulated environments

A demonstrable, auditable stop authority is exactly what assurance and boards ask to see.

Fleet scale

One agent or fifty — the same authority covers everything on the register, at once if needed.

What we guarantee

The promises the build must hold — on the record, by design.

Instant, pre-authorised

No approval chain at the moment it's needed — the authority was granted in advance.

Human-held

The authority sits with named people. No agent can trigger it, block it or bypass it.

Nothing off the record

Every halt and every restart is logged — who, what, when and why.

Safe stop

A halted agent stops cleanly — work in flight is held, not lost, and nothing commits after the stop.

Works with: Agent Identity (19) · Governance by Design (08) · HITL Control Points (09) · Supervision & Escalation (10)

RUNS ON

Microsoft Entra Agent ID · Copilot Studio · Dataverse · Purview audit

🔒 DELIVERED IN YOUR FAB · BLUEPRINT, FAST STAGE 3

The full design is our craft — and your Blueprint.

What you've read is the pattern: what it does, what it promises, where it fits. How it's engineered — the construct model and its enforcement — is WorkDynamics IP, delivered as part of your Functional Agentic Blueprint, configured to your function:

▪ The data model — every table, relationship and write-once rule, at build altitude
▪ The enforcement logic that makes the promises unbreakable, not aspirational
▪ The Copilot Studio configuration and orchestration
▪ The authority model — who holds the stop, at what scope
▪ The MCP tool surface and connections

See it configured for your function

Start with a free read of where your function is exposed, then walk it through with us on a 20-minute call.

Get your free exposure report