The most dangerous agent is one that passes every task test while acting from a different strategy.
The common mistake is to expand permissions because outputs look accurate. But local accuracy can hide strategic drift—especially when teams are already routing around stale doctrine with private prompts and shadow workflows.
Before any permission increase, run a Context Checksum. Have the responsible humans and the machine answer independently:
What are we doing? Why now? What are we refusing? What would change our mind? What local win would be globally wrong?
Compare substance, not wording. If the answers diverge, stop. Update the doctrine or the machine’s context, then run the check again. No matching checksum, no access to customers, money, production code, or irreversible commitments.
Don’t use this to force consensus during exploration or replace technical evaluations. Use it when autonomy is about to create real consequences.
Capability earns attention. Shared context earns permission.