What this boundary changes in the design
Tool permissions and data disclosure are governed separately. Authorising an action does not automatically grant access to the underlying sensitive data.
An Agent can contain several business activities. The process invokes one precise activity from one Agent revision and maps that activity’s typed inputs.
This keeps prompts, model/provider choices and guardrails behind a business-facing contract. Process authors depend on the activity outcome rather than on a free-form chat surface.
Output
Each agent operates within a defined scope: a specific business task, explicitly approved tools and a policy governing which data it can access. Sensitive values are pseudonymised where required, so the model receives only what it is authorised to see.
Tool permissions and data disclosure are governed separately. Authorising an action does not automatically grant access to the underlying sensitive data.
Agent Memory is a persistent working-context resource owned by an Agent definition and reusable across its revisions. Memory is optional: an Agent Task does not require a memory merely to run.
A process may use an Agent role when it needs continuity across several Agent Tasks, but the role does not choose which Agent or revision executes the work.
Processes can insert approval or review when confidence is insufficient, impact is high or an internal or regulatory rule requires human authority.
The model can contribute analysis or an explicitly authorised action; the process still materialises the actual control policy around that activity.