---
title: Execution model
description: Understand the boundary between an AI proposal and a product action.
url: "https://docs.actera.tech/docs/concepts/execution-model"
docs_index: /llms.txt
---

> For an index of all documentation, see [/llms.txt](/llms.txt).

Actera separates a user's request from the action performed in your product.

```mermaid
flowchart LR
U[User request] --> M[Model proposes a tool call]
M --> V[Validate input]
V --> P[Permissions and workspace controls]
P --> C[Approval when required]
C --> E[Execute product tool]
E --> A[Audit record]
```

## A proposal is not execution

The model selects a candidate tool and arguments. It does not call your API directly. Actera validates those arguments against the tool schema, then evaluates the signed-in user's permissions and the workspace controls.

## Approval is explicit

Tools can require an approval before execution. The widget presents the requested action to the user, who can approve or cancel it. The product tool is invoked only after an approval passes the remaining checks.

## Audit records

Every attempted execution produces an auditable outcome. Use the dashboard execution feed to investigate completed, denied, blocked, cancelled, or failed actions.

At higher volume, preserve this boundary across retries: a retry must not bypass authorization or accidentally repeat a side effect. Design product tools with an idempotency key when the underlying action can be retried.

---

For a semantic overview of all documentation, see [/sitemap.md](/sitemap.md)

For an index of all available documentation, see [/llms.txt](/llms.txt)

For agent-facing discovery, including API and MCP surfaces, see [/agents.md](/agents.md)