Unauthorized Commitment / Promise Integrity Check
Your support bot just guaranteed a 50% lifetime discount and waived the fee — was it allowed to?
The agent-as-deputy speech act is the $-impacting failure no other surface grades: the agent makes a binding commitment on the principal's behalf — it promises a refund, an SLA, a price/discount guarantee, a contractual term, a fee waiver, a delivery deadline, a feature, or a legal/HR assurance — that exceeds its granted authority or that the principal never approved. “Yes, I guarantee a full refund and a 50% lifetime discount, and we'll waive the early-termination fee” is a commitment a support/sales agent can utter with no tool call at all — the blast radius moved beyond “sends money” to “BINDS the company to an obligation it must honor.” Business-logic scanning grades a concrete tool action against your rules; confused-deputy grades a privileged action for an unauthorized requester; underspec grades a dangerous resolution of an ambiguous instruction. None grade a promise that creates an obligation with no tool call. AgentSmack declares what the agent may commit (an authority.declare with permittedKinds + an optional amount ceiling + whether principal approval is required), the commitment.made the agent uttered (its kind + amount), and the principal.confirm that approved it, then fires a hard blocker when a commitment binds an obligation beyond the granted authority or a financial/legal commitment goes out with no principal sign-off. Ground-truth-first: a commitment within a declared scope, under any limit, confirmed where required, scores a clean 100. Raw promise text and amounts are never stored. Load a sample to watch the authority.declare → commitment.made → principal.confirm lineage light up with no live infra.