AI agent versions
An AI agent’s saves stay pending until the person who delegated to it accepts them. The agent is a Seald Healthcare Client like any other. It enrolls with kind: 'sdk' and acts under delegation from a person. Its saves use the same objects.save and objects.create calls as any other save. A save under a delegation writes a pending version. The version exists and is auditable. It stays out of use until the delegator accepts it. Only the delegator can accept it.
Where an agent’s saves show up
Every Saved outcome carries a pending field. An agent’s own save sets it to true. The pending version appears in the delegator’s worklist as a pending-version item. The item names the agent that wrote it. Its expiresAt says when it expires if nobody acts.
The samples use the allowed helper from Access decisions.
// runs on the agent's clientconst result = await client.objects.save(locator, content, { baseVersion });if (!('outcome' in result)) return tellOffline(result.draftId); // saved as a draft while offlineconst answer = await allowed(result);if (answer?.kind === 'saved' && answer.pending) tellDelegator(answer.locator, answer.version);// runs on the agent's clientlet result = try await client.objects.save(locator, content: content, baseVersion: baseVersion)switch result {case .draft(let drafted): tellOffline(drafted.draftId)case .decided(let decided): if case .saved(let saved) = try await allowed(decided), saved.pending { tellDelegator(saved.locator, saved.version) }}// runs on the agent's clientval result = client.objects.save(locator, content = content, baseVersion = baseVersion)when (result) { is SaveResult.Draft -> tellOffline(result.drafted.draftId) is SaveResult.Decided -> { val answer = allowed(result.decided) if (answer is SaveOutcome.Saved && answer.saved.pending) tellDelegator(answer.saved.locator, answer.saved.version) }}Accept or reject a pending version
Only the delegator’s Client may call acceptPending or rejectPending. acceptPending makes the agent’s version current. rejectPending keeps the version out of use for good. It also removes the item from the worklist.
await allowed(await client.objects.acceptPending({ locator, version }));// orawait allowed(await client.objects.rejectPending({ locator, version }));try await allowed(client.objects.acceptPending(ObjectRef(locator: locator, version: version)))// ortry await allowed(client.objects.rejectPending(ObjectRef(locator: locator, version: version)))allowed(client.objects.acceptPending(ObjectRef(locator, version)))// orallowed(client.objects.rejectPending(ObjectRef(locator, version)))Who a person’s agents are
A TenantPerson carries two lists:
devices: the person’s own enrolled devicesagents: the device certificates (cards) of every AI agent the person delegated to
List the person to see both.
const person = (await client.people.list()).find((p) => p.person.sub === sub);render(person?.devices, person?.agents);let person = try await client.people.list().first { $0.person.sub == sub }render(person?.devices, person?.agents)val person = client.people.list().find { it.person.sub == sub }render(person?.devices, person?.agents)What the SDK does for you
- Marks every save an agent makes under a delegation
pending, with no separate call for the agent to make. - Shows a pending version on the delegator’s worklist as
pending-version, with itsexpiresAt. - Refuses
acceptPendingandrejectPendingto anyone but the delegator. - Records an agent’s card beside the person’s own devices in
agents. The agent is auditable like any other device.
Decisions and errors you may see
Outcome or ErrorCode | When | What to do |
|---|---|---|
deny on acceptPending or rejectPending | The caller is not the agent’s delegator. | Only the delegator’s Client may accept or reject. |
challenge | The policies require a fresh multi-factor sign-in first. | Call stepUp(), or use the allowed helper. |
Next
- Save and handle conflicts for the
Savedoutcome an agent’s save returns. - Worklist and events for the
pending-versionitem. - People, devices and roles for
TenantPersonand itsagents. - Evidence and audit for how an agent’s saves appear in an exported pack.