# Agent permission card

Blank template. Each field says what to record.

One card per shared agent: what it’s for, what it can reach and do, what needs approval, its limits and how to stop it.

## Agent and purpose

Name the agent and the one job it does.

[Your answer]

## Owner

Name the person responsible for the agent and its card.

[Your answer]

## Can read

List the systems and data it can read.

[Your answer]

## Can do on its own

List the actions it takes without approval.

[Your answer]

## Needs approval

List the actions that wait for a person.

[Your answer]

## Never

List the actions it must never take, enforced in its permissions.

[Your answer]

## Limits

Set limits on money, recipients, volume and time.

[Your answer]

## Reads from outside

List the untrusted content it reads, such as emails or web pages, and how that’s handled.

[Your answer]

## How to stop it

Say who can pause it and how.

[Your answer]

## How to undo its work

Say how to reverse what it did.

[Your answer]

## Review date

Say when the card and its permissions are checked.

[Your answer]

## Review

Owner: 
Agreed by: 
Date agreed: 
Next review: 

---

From The RUAI Standard (2026 edition), developed by Founderz in collaboration with Microsoft. https://responsibleai.founderz.com/toolkit/team-tools/agent-permission-card
Licensed under CC BY 4.0: https://creativecommons.org/licenses/by/4.0/
