Architecture guide
Can the AI read, or can it also change things?
Asking an assistant to explain an audience drop is not permission to change its rules. Define that boundary before connecting it.
Sources checked:
My proposed control model
-
Read
- Confirmed context
- Visible evidence
Inspect the audience and its dependencies with minimal permissions. A generated explanation still needs verification.
-
Propose
- Specific change
- Human review
Show what would change, on which object and with what consequences. Approval should cover that change, not a vague intention.
-
Execute and verify
- Authorised action
- Verified result
Record the action and inspect its result. Some external consequences, such as a sent message, cannot be undone.
What Adobe documents
Coworker and agents are more than search
Adobe documents Coworker, AI Assistant and Agent Orchestrator for tasks across its applications. Eligible customers transition to Coworker gradually. Do not assume every account has every capability.
Adobe: AI in CX EnterpriseContext depends on the product
Gateway MCP uses an active organisation. AEP, RT-CDP and AJO tools share sandbox context. CJA works with Data Views; Adobe Analytics uses report suites.
Adobe: Session context toolsConnecting does not grant universal access
Available tools depend on product entitlements and permissions. Being able to set context does not mean being able to read or change every organisational resource.
Adobe: AI in CX EnterpriseHow I would review it
- Separate read and write operations. Start with verifiable queries before allowing changes.
- Confirm the organisation, environment and affected object before authorising an operation. Do not rely on its display name alone.
- Record who authorised the action, what was requested and what changed. Test failures and recovery without assuming automatic rollback.
Product analysis and proposed controls. This is not an agent or MCP implementation I have delivered, or a new service with proven outcomes.