# Use Cases — The Agent Incidents ACP Stops, Catches, and Proves

Refund fan-out, deleted tables, the wrong customer's data in an email, a runaway model bill — the incidents production agents cause, and the control that stops each one. With live demos.

<div class="acp-section" style="padding-top:48px;padding-bottom:0;">
  <div class="acp-container">
    <div class="acp-card acp-card-pad" style="text-align:center;padding:48px 32px;">
      <h1 class="acp-hero-h1">The incidents you're one bad tool call away from</h1>
      <p class="acp-subtitle" style="max-width:660px;margin:16px auto 0;">
        Nobody adopts a control plane in the abstract. You adopt it because an agent can refund the wrong 200 customers, delete the wrong table, or email the wrong person's data &mdash; and your hand-rolled checks won't hold when you're not watching. Here's the failure mode by failure mode version.
      </p>
    </div>
  </div>
</div>

<!-- Failure modes -->
<div class="acp-section" style="padding-top:32px;">
  <div class="acp-container">
    <h2 class="acp-section-title" style="margin-bottom:20px;">Six failure modes, one choke point</h2>
    <div class="acp-grid-cards">

      <div class="acp-card acp-card-pad" id="money">
        <h3 class="acp-linkcard-title" style="font-size:17px;margin-bottom:8px;">The refund fan-out</h3>
        <p class="acp-linkcard-desc" style="margin-bottom:12px;">
          An agent misreads a policy and starts refunding customers &mdash; each one valid on its own, catastrophic in aggregate. Flat daily caps don't help; the agent cheerfully spends them to zero. ACP gates money tools on the <em>outliers</em>: unusual size asks a human, the Nth call in an hour trips, everything routine keeps flowing.
        </p>
        <a class="acp-linkcard-desc" style="color:#5b5bd6;" href="/blog/stop-your-agent-from-making-payments-without-approval">Stop your agent from making payments without approval &rarr;</a>
      </div>

      <div class="acp-card acp-card-pad" id="destructive">
        <h3 class="acp-linkcard-title" style="font-size:17px;margin-bottom:8px;">The destructive write</h3>
        <p class="acp-linkcard-desc" style="margin-bottom:12px;">
          <code>rm -rf</code>, <code>DROP TABLE</code>, <code>repo.delete</code> &mdash; the calls you can't undo. Prompt rules are advisory; the model ignores them under pressure or a poisoned tool response. ACP enforces policy on destructive operations at the call itself, outside the model, scoped by agent and by who it's acting for — audit-only until you configure deny-by-default for those tools.
        </p>
        <a class="acp-linkcard-desc" style="color:#5b5bd6;" href="/blog/stop-your-agent-from-deleting-your-database">Stop your agent from deleting your database &rarr;</a>
      </div>

      <div class="acp-card acp-card-pad" id="wrong-data">
        <h3 class="acp-linkcard-title" style="font-size:17px;margin-bottom:8px;">The wrong customer's data</h3>
        <p class="acp-linkcard-desc" style="margin-bottom:12px;">
          An agent acting for user A pulls something only user B should ever see &mdash; because the backend saw a valid service token, not a person. ACP binds every call to the identity of the user the agent is acting for, scopes access to what <em>they</em> can touch, and redacts PII before it reaches the model.
        </p>
        <a class="acp-linkcard-desc" style="color:#5b5bd6;" href="/blog/the-three-party-identity-gap">The three-party identity gap &rarr;</a>
      </div>

      <div class="acp-card acp-card-pad" id="runaway-bill">
        <h3 class="acp-linkcard-title" style="font-size:17px;margin-bottom:8px;">The runaway bill</h3>
        <p class="acp-linkcard-desc" style="margin-bottom:12px;">
          A loop that retries, re-plans, and re-reads until the invoice arrives. ACP meters every tool and model call, shows you which step is actually burning the money (it's usually one), and enforces hard budgets that warn the agent before cutting it off mid-task.
        </p>
        <a class="acp-linkcard-desc" style="color:#5b5bd6;" href="/blog/the-loop-tax">The loop tax: why agents are expensive &rarr;</a>
      </div>

      <div class="acp-card acp-card-pad" id="injection">
        <h3 class="acp-linkcard-title" style="font-size:17px;margin-bottom:8px;">The talked-into-it agent</h3>
        <p class="acp-linkcard-desc" style="margin-bottom:12px;">
          A poisoned web page or tool response instructs your agent to do something it shouldn't &mdash; and anything that lives in the prompt can be talked past. ACP's enforcement sits outside the model: whatever the agent was convinced of, the call still hits deterministic policy on the way through.
        </p>
        <a class="acp-linkcard-desc" style="color:#5b5bd6;" href="/blog/i-audited-7522-ai-agent-skills">What's actually inside 7,522 agent skills &rarr;</a>
      </div>

      <div class="acp-card acp-card-pad" id="prove-it">
        <h3 class="acp-linkcard-title" style="font-size:17px;margin-bottom:8px;">&ldquo;Prove what every agent did &mdash; and why it was allowed&rdquo;</h3>
        <p class="acp-linkcard-desc" style="margin-bottom:12px;">
          The question you can't answer when your logs say <code>service_account: 200</code>. ACP logs the <em>decision</em>, not just the action: who asked, which agent acted, which rule allowed it, what it touched, what it cost &mdash; per call, exportable.
        </p>
        <a class="acp-linkcard-desc" style="color:#5b5bd6;" href="/blog/what-280k-agent-tool-calls-look-like">What 285,000 governed tool calls look like &rarr;</a>
      </div>

    </div>
  </div>
</div>

<!-- Industry strip -->
<div class="acp-section">
  <div class="acp-container">
    <h2 class="acp-section-title" style="margin-bottom:8px;">Same control plane, any industry</h2>
    <p class="acp-muted" style="margin-bottom:20px;max-width:660px;">The failure modes above don't care what business you're in &mdash; only the data changes. A few concrete shapes:</p>
    <div class="acp-grid-cards">
      <div class="acp-card acp-card-pad" id="healthcare">
        <h3 class="acp-linkcard-title" style="font-size:16px;margin-bottom:6px;">Healthcare SaaS</h3>
        <p class="acp-linkcard-desc">Diagnostic assistants query patient records with the physician's identity verified on every call, access scoped by license type, PII redacted before the model, every query logged &mdash; the audit trail HIPAA asks for.</p>
      </div>
      <div class="acp-card acp-card-pad" id="fintech">
        <h3 class="acp-linkcard-title" style="font-size:16px;margin-bottom:6px;">Fintech &amp; lending</h3>
        <p class="acp-linkcard-desc">Credit queries scoped to each officer's assigned borrowers, SSNs masked before the model, per-officer rate limits on data pulls, identity on every row.</p>
      </div>
      <div class="acp-card acp-card-pad" id="saas">
        <h3 class="acp-linkcard-title" style="font-size:16px;margin-bottom:6px;">SaaS shipping AI features</h3>
        <p class="acp-linkcard-desc">Every tool call arrives with the customer's verified identity, tenant isolation enforced at the gateway, per-customer budgets that catch abuse &mdash; ship the AI integration without building the control layer first.</p>
      </div>
      <div class="acp-card acp-card-pad" id="enterprise">
        <h3 class="acp-linkcard-title" style="font-size:16px;margin-bottom:6px;">Internal copilots</h3>
        <p class="acp-linkcard-desc">SSO identity through every request, tool access scoped by role, per-user spend limits, every action attributed &mdash; the answer to &ldquo;what did the copilot just do, and as whom?&rdquo;</p>
      </div>
    </div>
  </div>
</div>

<!-- CTA -->
<div class="acp-section">
  <div class="acp-container">
    <div class="acp-card acp-card-pad" style="text-align:center;padding:48px 32px;">
      <h2 class="acp-section-title">Put a control plane between your agents and the incident</h2>
      <p class="acp-muted" style="max-width:520px;margin:8px auto 0;">
        Self-host with the MIT-licensed modules, or use ACP Cloud &mdash; one install, and your next agent run shows up governed in the console.
      </p>
      <div class="acp-btn-row" style="justify-content:center;margin-top:24px;">
        <a href="https://cloud.agenticcontrolplane.com/login?from=%2Fonboarding" class="acp-btn acp-btn-primary" data-track="Solutions CTA: Start Free">Start for free</a>
        <a href="/reference-architecture" class="acp-btn" data-track="Solutions CTA: Architecture">Architecture deep dive</a>
      </div>
    </div>
  </div>
</div>
