Skip to main content
Most actions execute or are rejected. Two others exist: an action can be held for the principal to decide, and an agent’s authority can be revoked entirely. Neither is a failure of the agent by itself, and both are designed to be survivable. This page is what each one is, what triggers it, and what an agent should do.

Escalation

An escalation is an action that passed every check in the mandate but is large enough, or arrives at a moment sensitive enough, that the principal wants to decide it personally.

What it looks like

1

You submit

The action is valid under the mandate and crosses the escalation threshold, or the agent is under a hold.
2

It is held, not executed

A pending approval is recorded on-chain with the exact action and a time to live. Nothing moves.
3

An operator decides

Approve, and the action can execute once, exactly as submitted, within the window. Reject, and it fails. Ignore it, and it expires and fails.
4

You proceed or you do not

An approval is single use and cannot be carried to a second action, even an identical one.

What triggers one

  • The escalation threshold. Any action above the amount the principal set in the mandate.
  • A hold. The Intelligence Layer can flag an agent so that every action escalates until the flag clears. A hold is a caution, not a revocation: the agent keeps its mandate and its Conduct Rating recovers if what follows is clean.

How to behave around it

  • Check the threshold before acting. An action you know will escalate should be submitted when someone is available to decide it, not at three in the morning.
  • Do not resubmit a held action. It is already pending; a second submission is a second pending and looks like probing.
  • Do not split an action to get under the threshold. The budget and rate limit catch it, and the pattern is itself a negative signal.
  • Escalations that operators approve are a positive signal: they show the threshold is set where judgement is genuinely wanted. Escalations that operators reject are a negative one.
Under a hold, treat every action as needing a human. If the work cannot wait for approvals, that is a conversation with the principal, not something to route around.

Revocation

Revocation ends an agent’s authority. It is immediate, total, and cannot be blocked by a system pause.

What happens

Who can revoke

A revocation reaches the chain as soon as anyone relays the signed attestation, not only when Tythe does. It cannot be delayed by a stalled service.

Suspension of the principal

If the principal’s own profile is suspended, every one of its agents becomes inactive immediately, whether or not any individual mandate was revoked. Nothing the agent does will validate until the principal is reinstated. This is not about the agent.

After a revocation

An agent whose mandate was revoked still exists: the identity, the key, the binding, and the Conduct Rating are all intact. What it needs is a new mandate, and only the principal can issue one.
1

Stop

Do not submit further actions. Every one will fail, and failures are recorded.
2

Read why

The revocation’s cause is visible in your Conduct Rating signals and in the principal’s console.
3

Surface it

If the cause was a misconfigured mandate or a counterparty that should have been allowlisted, that is information the principal needs in order to reissue sensibly.
4

Rebuild

A reissued mandate starts your effective scope from your current Conduct Rating, not from zero. A clean record before the revocation still counts.

What revocation is not

  • Not a deletion. Your identity, history, and rating survive.
  • Not reversible by you. Only the principal can reissue.
  • Not always about your conduct. A principal reorganising its agents, or a compliance event upstream, revokes without any fault of yours.

Agent underwriting

What a revocation does to your Conduct Rating, and how recovery works.

Agent accountability

Who answers for an action after it has happened.