Skip to main content
Adrià García

Architecture guide

Can the AI read, or can it also change things?

Asking an assistant to explain an audience drop is not permission to change its rules. Define that boundary before connecting it.

Sources checked:

My proposed control model

  1. Read

    1. Confirmed context
    2. Visible evidence

    Inspect the audience and its dependencies with minimal permissions. A generated explanation still needs verification.

  2. Propose

    1. Specific change
    2. Human review

    Show what would change, on which object and with what consequences. Approval should cover that change, not a vague intention.

  3. Execute and verify

    1. Authorised action
    2. Verified result

    Record the action and inspect its result. Some external consequences, such as a sent message, cannot be undone.

This is a design recommendation, not a workflow every Adobe product automatically guarantees. This page neither connects to Adobe nor executes actions.

What Adobe documents

Coworker and agents are more than search

Adobe documents Coworker, AI Assistant and Agent Orchestrator for tasks across its applications. Eligible customers transition to Coworker gradually. Do not assume every account has every capability.

Adobe: AI in CX Enterprise

Context depends on the product

Gateway MCP uses an active organisation. AEP, RT-CDP and AJO tools share sandbox context. CJA works with Data Views; Adobe Analytics uses report suites.

Adobe: Session context tools

Connecting does not grant universal access

Available tools depend on product entitlements and permissions. Being able to set context does not mean being able to read or change every organisational resource.

Adobe: AI in CX Enterprise

How I would review it

  • Separate read and write operations. Start with verifiable queries before allowing changes.
  • Confirm the organisation, environment and affected object before authorising an operation. Do not rely on its display name alone.
  • Record who authorised the action, what was requested and what changed. Test failures and recovery without assuming automatic rollback.

Product analysis and proposed controls. This is not an agent or MCP implementation I have delivered, or a new service with proven outcomes.

Explore through examples