Answering is one thing. Updating, sending, refunding, booking, publishing, deleting, and changing are different. Once AI moves from suggesting a response to altering a real system, the design question becomes authority.
Consider a support request. The model may understand the message and draft the right reply. Finishing the job could require finding the correct account, checking an entitlement, selecting an allowed remedy, asking for approval, updating the case, sending the response, and scheduling a follow-up. Each verb touches a different permission and creates a different failure.
A useful agent knows what it may read, what it may prepare, what it may change, what a person must approve, and when to stop. That boundary belongs in the product and infrastructure. A sentence in the model's prompt cannot enforce it.