The Two Seconds at the Door
Why your AI agent cannot be trusted yet — and the five questions it must answer before it acts.
A knock sets off more work than it appears to
Before the person inside has crossed the room, they have recalled whether they were expecting anyone, remembered that a delivery was due, and judged from the sound whether one person is outside or several. They cross the room, look through the glass before unlatching anything, and decide in the same instant whether to open the door, how far, and whether to call someone else over first.
The sequence takes perhaps two seconds and feels effortless. It is not effortless. It is a rapid assembly of memory, expectation, sensory evidence, and a judgment about who belongs on the other side of the threshold, all completed before the person acts.
An agentic AI system faces the same problem in structural terms. The knock is a signal, which in these systems is called a triggering event: a meeting concludes, an email arrives, a portfolio breaches a threshold. On that signal the system has to assemble the context that turns a bare event into an informed action, and it has to do so within the boundary of what it is permitted to see.
The difference from the AI most executives have already used is precise and consequential. When a person queries a chatbot, the person supplies the context by choosing what to type. In an agentic system no person sits in that loop. The agent has to locate the relevant context itself, decide what to do with it, and determine whom to involve, before it produces anything at all.
Doing this well is now the central engineering and governance problem in enterprise AI, and it is routinely misdiagnosed as a problem of model quality.
A firm that can answer all five questions for every agent it runs has a context capability. A firm that can answer only the first has a library.
Five questions an agent must answer before it acts
Reduced to essentials, context is the set of answers an agent assembles, on a signal, to five questions. Each resides in a different place inside the firm, and most of them cannot be bought.
Knowledge
What does it know? The written rules sit in policy libraries and compliance systems. The unwritten rules, the ambient state, and the judgment reside overwhelmingly in the collaboration layer: in email, in shared drives, in messaging tools. Those are the places no one lists when asked to name the firm's systems of record, and they hold the most valuable knowledge the firm possesses.
Similarity retrieval answers the question of what looks relevant. A graph answers the question of what is actually connected. The first fails when the decisive fact bears no textual resemblance to the signal.
Memory is what separates an agent that is merely competent from one that is continuous. An agent without it greets every returning user as a stranger.
Entitlement
Most neglectedWhat is it permitted to see, and on whose behalf? The person at the door looks through the glass before opening because not every caller is admitted and not every room is open to every visitor.
When a firm assembles its library by having a model read, summarize, and cross-reference its documents, a fact extracted from a restricted source and written into a summary loses the access control that governed the original. The barrier applied to the document. The derived summary inherited nothing.
A firm that builds its knowledge base without engineering for this has constructed an efficient mechanism for making restricted information broadly legible — and it has done so without anyone deciding to.
Marshalling
Has it brought the right context and the right participants to bear, and only those? Gathering the relevant context and deciding whom to involve are not sequential steps. They are one judgment.
Executives tend to assume that more context, and more agents, must produce a better result. The assumption is mistaken, and setting it aside is much of the skill. The person at the door does not summon the entire household for every caller. They convene the smallest sufficient response.
The graph is the firm's address book of relationships. The connector — of which the Model Context Protocol has become the common standard — is the telephone line it uses to place the call.
Currency & Provenance
Is what it knows still true, and where did each piece come from? Context has a shelf life. An agent acting on a fact that was accurate last quarter can fail as badly as one acting on no fact at all. A capability records not only what is true but when it became true and whether it still holds.
Provenance has a second part, discussed far less often and mattering more. Agents do not only consume context. They produce it. A mistaken conclusion, recorded once, can harden into an apparent fact and propagate through the system.
Governing what an agent may see has a counterpart of equal importance and far less scrutiny: governing what it is permitted to write back, and what it is permitted to teach.
What performs the work: the harness
These five questions describe the properties of good context. They do not, on their own, identify what performs the work. The model reasons; it is the analytical faculty. A faculty for reasoning accomplishes nothing on its own. The harness is the surrounding machinery: the orchestration loop that plans and directs, the execution of tools, the enforcement of policy, the management of state and memory across steps, and the writing of the record.
Of the five components, knowledge is the one a firm stores. The other four are performed by the harness at the moment of action.
The harness performs four of the five components at the moment of action. Only knowledge sits at rest, in the library.
A firm can acquire a library. The capability that converts a library into trustworthy action is something it has to build for itself.
The part that cannot be procured
Every action an agent takes is a hypothesis — its best estimate of the correct move given what it has assembled. A firm does not build a context capability to make its agents certain. It builds one to make their hypotheses worth acting on.
Context is not something to be procured
A firm can buy models, tools, and much of the raw library. It cannot buy the four components that make context trustworthy, because each has to be wired to the firm's own people, permissions, systems, and obligations. A vendor offering to sell a context layer is offering the library and describing it as the entire structure.
Entitlement cannot be retrofitted
A permission boundary imposed on a system already gathering and synthesizing context is far harder to install than one designed in from the first use case. The disciplined course is to treat the first and smallest use case as the place to get entitlement right, precisely because it is small.
The harness stays under the firm's control
A firm that delegates its harness to a vendor has delegated the enforcement of its own compliance obligations to a system it cannot inspect. It is also the element most frequently rebuilt as models advance, and a firm should plan for that rhythm rather than be surprised by it.
The overlooked implication is organizational
The most valuable context a firm holds is the judgment its experienced people carry and have never written down. An agent, like a new hire, should be granted autonomy only over what it has shown it can handle — and what it is permitted to learn and pass on should be governed as carefully as what it is permitted to see.
Five questions for anyone selling you “context”
The word context is now attached to a great many products.
Five questions separate those built for a regulated firm from those that will produce confident, well-sourced, and unauditable errors.
Vendors who answer these plainly are worth engaging further. Vendors who deflect have already made the decisions on the firm's behalf.
Read the full chapter
The complete chapter sets out all five components in full, the architecture beneath them, the harness that performs the work, and the questions to put to any vendor selling you “context”.
Get the Full Article
Enter your details to access Chapter 4 of the AI Edge Playbook.
We use your details to send the chapter and occasional AI Edge updates. Unsubscribe at any time.