Skip to content

AI agent versions

An AI agent’s saves stay pending until the person who delegated to it accepts them. The agent is a Seald Healthcare Client like any other. It enrolls with kind: 'sdk' and acts under delegation from a person. Its saves use the same objects.save and objects.create calls as any other save. A save under a delegation writes a pending version. The version exists and is auditable. It stays out of use until the delegator accepts it. Only the delegator can accept it.

Where an agent’s saves show up

Every Saved outcome carries a pending field. An agent’s own save sets it to true. The pending version appears in the delegator’s worklist as a pending-version item. The item names the agent that wrote it. Its expiresAt says when it expires if nobody acts.

The samples use the allowed helper from Access decisions.

// runs on the agent's client
const result = await client.objects.save(locator, content, { baseVersion });
if (!('outcome' in result)) return tellOffline(result.draftId); // saved as a draft while offline
const answer = await allowed(result);
if (answer?.kind === 'saved' && answer.pending) tellDelegator(answer.locator, answer.version);

Accept or reject a pending version

Only the delegator’s Client may call acceptPending or rejectPending. acceptPending makes the agent’s version current. rejectPending keeps the version out of use for good. It also removes the item from the worklist.

await allowed(await client.objects.acceptPending({ locator, version }));
// or
await allowed(await client.objects.rejectPending({ locator, version }));

Who a person’s agents are

A TenantPerson carries two lists:

  • devices: the person’s own enrolled devices
  • agents: the device certificates (cards) of every AI agent the person delegated to

List the person to see both.

const person = (await client.people.list()).find((p) => p.person.sub === sub);
render(person?.devices, person?.agents);

What the SDK does for you

  • Marks every save an agent makes under a delegation pending, with no separate call for the agent to make.
  • Shows a pending version on the delegator’s worklist as pending-version, with its expiresAt.
  • Refuses acceptPending and rejectPending to anyone but the delegator.
  • Records an agent’s card beside the person’s own devices in agents. The agent is auditable like any other device.

Decisions and errors you may see

Outcome or ErrorCodeWhenWhat to do
deny on acceptPending or rejectPendingThe caller is not the agent’s delegator.Only the delegator’s Client may accept or reject.
challengeThe policies require a fresh multi-factor sign-in first.Call stepUp(), or use the allowed helper.

Next