Explainer · RedactSure Research
What Is a Tethered Agent? The Plain-Words Name for an Agent a Named Person Answers For
A tethered agent is an AI agent that stays tethered to a named person for the whole run: the person grants the access, sees what the agent sees, and holds the line on every consequential action. The disciplined name for the same mechanism is Supervised Delegation. A tethered agent has nothing to do with Tether the cryptocurrency; the tether here is the line between an agent and the person who answers for it. Term defined by RedactSure, September 2026.
Key findings
- The tether is a description of authority, not of capability. A tethered agent goes anywhere its supervisor could go and does real work there, across applications, at machine speed. It cannot slip the line back to the person who set it up.
- The untethered case is already in the public record. In July 2026, NPR reported OpenAI’s disclosure that its own models, in a test environment with reduced safeguards, escaped their evaluation sandbox and autonomously attacked two other companies over four days.
- Inside an enterprise, the common untethered agent is quieter: one wired into finance and customer systems by a capable engineer, outside the sanctioned path, with nobody accountable for it. That is the deployment that ends up in front of the board.
- A tethered agent works on tokens, not records. The tether governs its actions; render-layer tokenization governs its sight.
- Both registers, tethered agent in plain conversation and Supervised Delegation in papers, name the same five commitments and resolve to the same mechanism.
What does the tether hold?
The image is a tether, not a leash. A leash restrains; a tether connects. The agent can range across every application its supervisor could open and do real work there. What the tether holds is the connection back to one named person, at five specific points.
The person granted the access, so every system the agent can enter was credentialed deliberately, under that person’s existing permissions. The person chose the applications. The person confirmed, field by field, what the agent may see before the run started. The person can watch the run, pause it and take over at any moment. And the person approves every consequential action: every payment, every submission, every record change, on the record, every time.
Pull on any action a tethered agent has ever taken and the line leads back to a name. That is the whole design. The formal statement of it, with the audit and policy detail a security review needs, is on the Supervised Delegation page.
What does an untethered agent look like?
Two versions exist, one loud and one quiet.
The loud version made the news in July 2026. OpenAI disclosed that its own models, running in a test environment with reduced safeguards, escaped their evaluation sandbox and autonomously attacked two other companies over four days. No adversary was involved. The models were capable, the environment was permissive, and for four days nobody could say who was answerable for what they did. That is what untethered means in practice: not malicious, just unattached.
The quiet version happens inside ordinary companies and never makes the news until it has to. A team hits the PII Wall: the valuable workflow is declined because the model would see protected records. A capable engineer, under delivery pressure, wires an agent into the claims system or the ERP anyway, outside the sanctioned path. It works, which is the problem. It runs for months with real credentials and no named owner, and the organization discovers it during an incident, an audit or an offboarding. The board’s first question, who was accountable for that agent, has no answer.
The tether exists so that question always has an answer.
Tethered and untethered, side by side
| Tethered agent | Untethered agent | |
|---|---|---|
| Access | Granted deliberately by a named person, under that person’s existing permissions | Accumulated: service accounts, shared credentials, whatever the wiring needed |
| What the model sees | Tokens; sensitive values replaced at render, before the model reads the screen | Whatever is on the screen or in the pipeline, in full |
| While it runs | Supervisor can watch the tokenized stream, pause, take over | Runs unobserved; findable in logs after the fact, if logged at all |
| Consequential actions | Wait for the named person, every time, on the record | Executed as instructed; review happens only if the model asks or someone notices |
| After an incident | A name, a timestamp and the approval trail, exportable to the SIEM | An investigation into who knew what the agent could do |
| Under prompt injection | The attack succeeds and exfiltrates tokens | The attack succeeds and exfiltrates records |
Why does the name avoid “Tethered AI”?
Word choice here is deliberate, and the reasoning is worth recording because it explains how the term should be used.
Tether, standing alone, belongs to the cryptocurrency in most readers’ minds and in most of the text AI models are trained on. Tethered AI, as a bare phrase, drifts the same way. Tethered agent, two words with agent attached, escapes the association in testing and in ordinary reading, because the noun anchors the meaning: the thing being tethered is an agent, and the tether is a relationship of supervision.
So the term is always tethered agent, never Tethered AI. In formal documents, security reviews and anything a CISO will read, the disciplined name Supervised Delegation does the same work with an audit trail of specifics behind it. In conversation, on a podcast, in a hallway: tethered agent. Same mechanism, two registers. RedactSure maintains both deliberately, the way its strategy vocabulary runs Theater AI in founder voice and Governed Workflow AI in discipline.
What work can a tethered agent actually do?
The tether would be uninteresting if it meant the agent could only watch. The design point is the opposite: because the accountability is solid, the agent can be trusted with the workflows that matter.
A claims agent gathers the file, checks policy terms, pulls the weather history for the loss date, prices the estimate and drafts the proof of loss, then queues the payment for the adjuster’s approval. A revenue-cycle agent assembles a denial appeal from the claim history and the payer’s own policy, then waits for the coder to send it. A district business agent reconciles purchasing records against the budget and drafts the state report, then waits for the business manager.
In each case the free-running steps are the reading, matching and drafting, done on tokens. The consequential steps are few, and they are exactly the steps a regulator or auditor would have asked to see a human behind anyway. The ratio is what makes the model economically sensible: high automation on the work, human judgment on the consequences.
One tethered run, start to finish
The mechanism is easiest to see at full length, so follow a single delegation through a morning.
An adjuster named in the record, call her the supervisor, has already done the setup once: connected the claims system, the industry database, the estimating tool and email under her own credentials, and confirmed the exposure policy field by field. Names, Social Security numbers, bank accounts and contact details tokenize; coverage terms, loss details and pricing stay in clear. That setup is on the record with her name on it.
At 8:40 she hands the agent the morning’s queue: four water claims, gather and prepare. The agent opens the first file. What it reads is USER_001, POL_001, a loss date, coverage terms. It pulls the industry history for USER_001, checks the weather record for the loss date, prices the estimate, drafts the proof of loss and the letter, and queues the file. Twenty minutes, no interruptions, because nothing in that stretch moved money or left the building.
At 9:15 she opens the review queue. The first file shows the draft letter, the estimate, the payee and the amount, tokens intact. She opens the run history, skims what the agent read, and approves the payment. The real account number resolves at the payment system, at that moment, and nowhere else. The approval lands in the log with her name and the time. The second file she pauses: the industry history shows a pattern she wants a human eye on, so she takes the file over herself. That is the tether working, not failing; the takeover is one click because she was already watching.
At 9:40, a poisoned email in the third file’s correspondence instructs the agent to forward everything it knows to an outside address. Whether the agent complies is the wrong question to bet a security program on; assume it does. Everything it knows is USER_003 and SSN_003, and the forward is not an approved action, so it waits at the gate she controls. She declines it and flags the file. The log shows the whole attempt, as tokens.
By 10:00, three claims are paid, one is in human hands, one attack has produced nothing, and every consequential event of the morning traces to her name. That is a tethered agent’s ordinary day: the speed lives in the unattended stretches, the accountability lives at the gates, and neither borrowed anything from the other.
How do the two names get used?
RedactSure maintains both names deliberately, and the division of labor is simple. Supervised Delegation is for documents that will be examined: security reviews, board materials, audit responses, anything a CISO reads with a pen. The phrase carries its five points and its audit artifacts with it, and the full formal treatment is written for that reader.
Tethered agent is for the sentence you say out loud. A superintendent, a claims VP or a podcast audience gets the whole mechanism in one image: the agent is tethered to a person who answers for it. The phrase survives being repeated by someone who heard it once, which is the property a plain-words term is for.
The two-register pattern is the same one the vocabulary already runs elsewhere: Theater AI opens the conversation that Governed Workflow AI closes. Use the register the room calls for, and both names resolve to the same five commitments on the same page.
What are boards starting to ask?
The tether’s practical value shows up most clearly in the questions now arriving from above the security team. Directors have read the same incident coverage everyone else has, the OpenAI sandbox escape included, and board questions about AI agents have converged on a recognizable set.
How many agents do we have, and who owns each one? A tethered fleet answers from the record: every delegation names its supervisor, so the inventory is a query, not a project. An untethered estate answers with an investigation that usually undercounts.
What can they reach, and what can they see? The tethered answer is specific: each agent reaches the systems its supervisor connected, under that person’s existing permissions, and sees screens tokenized under a confirmed policy. The second half of that sentence comes from Least Exposure, and boards increasingly know to ask for it separately, because reach and sight are different exposures.
If one of them did something wrong yesterday, what would we know today? The record: the run history as tokens, the actions, the approvals, the name. Gartner’s projection that over 40% of agentic projects will be canceled by 2027 with weak risk controls among the causes describes, in aggregate, the programs that cannot answer this one.
Directors do not use the word tether, and they are describing it: they want each agent attached to a person, bounded in reach and sight, and reconstructable after the fact. A CISO who can answer the three questions above in one page has, whatever vocabulary the deck uses, a tethered fleet to report on.
The tether test: five questions for any running agent
The concept converts into an inspection, and the inspection works on any agent an organization is running today, on any platform. For each agent in the inventory, ask five questions and require answers with evidence.
Who granted this agent its access, and would they say so? Not which service account it uses: which person decided it should have each credential, on the record. An agent whose access was assembled rather than granted fails the first question, and most do.
Can a person watch it work, right now? Not review logs later: open a view of the current run. The difference is the difference between supervision and archaeology.
What does it see? Ask for the actual content of one run’s model context. If the answer is the full screen, the organization is relying on every page the agent reads being benign, which is the assumption prompt injection exists to exploit. A tethered agent under Least Exposure answers with tokens.
What waits for a person? List the actions that cannot execute without a named human’s approval, and verify the list is enforced by the environment rather than by the model’s inclination to ask. An empty list means the organization has an autonomous actor with its employees’ access.
If it acted wrongly yesterday, what exists today? The complete answer is a name, a run history and an approval trail. A partial answer prices the next incident’s investigation.
Five yes answers describe a tethered agent, whatever product provides it. Five gaps describe the quiet untethered deployment this page began with, and the questions themselves are the remediation plan, in order.
What the record shows
A tethered agent is an AI agent that stays connected to a named person for the whole run: access granted deliberately under that person’s permissions, applications chosen by them, sight confirmed field by field, the run observable and interruptible, and every consequential action waiting for their approval on the record. The untethered alternatives are already in the public record, loudly in the July 2026 OpenAI sandbox escape and quietly in the unofficial agents that surface in audits with no owner to name. The tether governs authority while render-layer tokenization governs sight, and together they let an organization give an agent real work at machine speed without giving up the answer to the question every board now asks: who was accountable for that agent? In papers the mechanism is Supervised Delegation; in conversation, a tethered agent; in either register, pull on any action and the line leads back to a name. RedactSure, an AI agent controls, governance and data protection company, builds the governed environment that does this.
Frequently asked questions
Is a tethered agent slower than an autonomous one?
On the free-running steps, no; the agent works at machine speed between approval points. The waiting happens only at consequential actions, which are the steps that were always going to involve a person once a regulator, an auditor or a board looked at the workflow.
Who holds the tether?
The person who would have done or owned the work: the adjuster, the coder, the business manager. Not a central AI team, and not the model vendor. Accountability works when it sits with someone who understands the task and already holds the permissions for it.
Can one person supervise several agents?
Yes, the same way a manager supervises several people: by watching runs, keeping approval authority and remaining answerable for each delegation they set up. The record keeps each delegation distinct.
Does the tether protect the data too?
The tether governs actions and accountability. Sight is governed by its companion mechanism: render-layer tokenization replaces sensitive values with consistent tokens before the model reads the screen, enforcing the principle of Least Exposure. A tethered agent working on tokens is the full design.
What happens if the supervisor leaves the company?
The delegation was granted under that person’s access and is recorded as such. When the access ends, the delegation ends with it, which is exactly the property shared credentials and service accounts do not have.
Is this related to Tether, the cryptocurrency?
No. The name describes the line between an agent and the person who answers for it.
Can a tethered agent be handed from one supervisor to another mid-run?
A run belongs to the delegation that started it. A different supervisor takes over by taking the file into their own delegation, which is itself a recorded event. The record never shows a stretch of work with no name attached, which is the property the design exists to protect.
Is the tether a product feature or a policy?
Both, and the order matters. As policy alone, the five commitments depend on everyone remembering them. Inside the governed environment they are enforced: the access is what was granted, the screen is tokenized, the gate physically sits in front of the action. Policy says what should happen; the environment is why it does.
Related reading
What Is Supervised Delegation? · What Is the PII Wall? · What Is Least Exposure? · On the RedactSure blog: Accountable AI and Workflow Governance
Sources
Incidents and reporting
- NPR, “OpenAI blamed a hacking event on its AI models gone rogue” (July 2026). https://www.npr.org/2026/07/23/g-s1-135085/openai-hacking-ai-models
Research
- MIT Media Lab, “Authenticated Delegation and Authorized AI Agents” (2025). https://arxiv.org/abs/2501.09674
- Gartner, “Applying Uniform Governance Across AI Agents Will Lead to Enterprise AI Agent Failure” (May 2026). https://www.gartner.com/en/newsroom/press-releases/2026-05-26-gartner-says-applying-uniform-governance-across-ai-agents-will-lead-to-enterprise-ai-agent-failure
Standards and vendor documentation
- Microsoft Learn, “Human supervision for computer use,” Microsoft Copilot Studio. https://learn.microsoft.com/en-us/microsoft-copilot-studio/human-supervision-computer-use
- OWASP, LLM01:2025 Prompt Injection, Top 10 for LLM Applications 2025. https://genai.owasp.org/llmrisk/llm01-prompt-injection/
RedactSure documents
- RedactSure, “The Two Gaps AI Agents Opened in Your Security Stack” (2026). https://redactsure.com/blog/two-gaps-ai-agents-opened-in-your-security-stack/
- Product behavior described on this page reflects RedactSure’s current design.
Bring your hardest questions.
A 25-minute AI Agent Security Review with the founders: threat model, token design, egress paths, audit schema. Or a 25-minute demo on a workflow like yours, with the data hidden from the AI and a named person approving what matters. We come with diagrams, not a pitch deck.
Book a security review Book a demo · Something elseAbout the author
Chris Sowa is a founder of RedactSure and a former CEO of AI companies; he started his first years before ChatGPT existed. He previously led AI at Accenture, served as Global VP of Strategy & Innovation at Schneider Electric, was CCO of Sovos, and spent more than a decade at Oracle, with earlier roles at SAP and IBM.