---
title: "AI agent execution: implementation checklist"
description: "Find the implementation for provider credential isolation, approvals, shared impact limits, idempotency, recovery, halt and action versioning."
---

Anlyon executes named actions on your agent's behalf. Start with a hosted action in a test environment, then add controls for the operation's consequences. This map connects common implementation questions to the precise contract.

## Choose the execution path

| Path | Credential and execution location | Outcome evidence |
| --- | --- | --- |
| [Local approval gate](/guides/approval-gates) | Your process | Approval decision only |
| [Hosted template action](/execution/actions) | Anlyon | HTTP response or unknown outcome |
| [Governed effect](/execution/governed-effects) | Anlyon, for an action with an adapter or a declaration | A receipt grade, with provider, manual or unverified evidence labelled as such |

Three adapters exist: Stripe refunds, updates to one existing GitHub text file, and Resend email sends. Any other HTTPS API can be governed as a [declared action](/guides/any-http-api). A limit and a grade apply to an action with an adapter or a declaration. The [beta policy](/beta) describes availability limits.

## Match the control to the question

| Question | Implementation | Boundary to preserve |
| --- | --- | --- |
| Can the agent refund without a provider key? | [Quickstart](/quickstart), [secrets](/execution/secrets) | The runtime still has an Anlyon key. Remove direct provider credentials |
| How do I prevent credential misuse after prompt injection? | [Authentication](/authentication), [policies](/trust-control/policy-as-code) | Allowed actions can still be misused. This is not injection detection |
| How do refunds, deploys or emails wait for a person? | [Approvals](/trust-control/approvals) | Local gates and hosted actions enforce different boundaries |
| How do all agents share a refund or mutation cap? | [Impact limits](/execution/impact-limits) | Governed actions within one environment |
| What if a tool call times out after the write? | [Idempotency](/execution/idempotency), [outcomes](/execution/outcomes) | Unknown does not mean failed. Template and governed recovery differ |
| How do I stop new external calls? | [Environment halt](/trust-control/environments) | Already accepted external requests are not recalled |
| How do I keep staging away from production? | [Environment scoping](/trust-control/environments) | Anlyon row isolation does not separate an external provider account for you |
| How do I keep the approved target and version unchanged? | [Previews](/execution/previews), [version pinning](/trust-control/promotion) | Preview binding and provider freshness are different guarantees |
| What proves a write happened? | [Governed-effect evidence](/execution/governed-effects) | A template `2xx` is not provider verification |
| How do I integrate my framework? | [LangGraph](/guides/langgraph), [SDKs](/guides/typescript-sdk), [examples](/guides/examples) | Resume state is not reviewer authentication |
| How do Claude Code and Cursor use hosted actions? | [Claude Code](/ai-tools/claude-code), [Cursor](/ai-tools/cursor) | Keep administrative permissions and provider keys outside the coding agent |
| Can the records support oversight reviews? | [Compliance](/trust-control/compliance), [analytics](/advanced/analytics) | Technical controls do not establish legal compliance |

## Verify the failure paths

In a non-production environment, exercise a denied approval, expired preview, revoked requester, halted environment, duplicate request and unknown provider outcome. Check the stored invocation or effect as well as the response the agent received. A successful example only verifies the path that ran.

For architectural evaluation, see [execution versus authorization](https://anlyon.com/guides/ai-agent-execution-layer) and [tool selection](https://anlyon.com/guides/ai-agent-tools-comparison). For the first call, use the [quickstart](/quickstart).
