# Agent Actions

> What an "action" is in the managed-agent runtime (Flow B), and how it executes.

_Verified against `app/Services/Actions/*` and `app/Services/Agents/*` on 2026-07-23._

---

## Definition
An **agent action** is a slug (e.g. `reject`, `request_more_info`, `move_to_review`) that a managed agent proposes. It is **not** free-form: `AgentActionExecutor` maps the slug → a `LabelOption` on the `action` label, then applies it through the **canonical** `StartupLabelActionService` / `InvestorLabelActionService` — the same path used by the dashboard, REST API, and MCP.

- Executed with `ActivityContext::SOURCE_AGENT` (audited as agent-originated).
- **No action logic is duplicated** — agents reuse the one canonical transition path.
- Side effects follow the LabelOption config: group move, notifications, meeting cancellation, audit.

## Allowed actions per agent
From `config/agent_runtime.php` (`allowed_actions`), enforced by the structured-output validator:

| Agent | Allowed actions |
|-------|-----------------|
| `intake_triage` | `move_to_review`, `reject`, `stop` |
| `prescreen` | `request_more_info`, `request_meeting`, `reject` |

> These enums are annotated in config as **"pending authoritative confirmation"** → treat exact membership as **Unknown - requires confirmation** until verified against the live request spec.

## Execution ownership (locked)
Actions are **executed by Numu**, not by Make.com. After approval, `AgentActionExecutor` runs the canonical service. Make orchestrates/reasons only. See [`../01-architecture/ai-architecture.md`](../01-architecture/ai-architecture.md).

## Supporting classes
`app/Services/Actions/` — `AbstractLabelActionService`, `StartupLabelActionService`, `InvestorLabelActionService`, `ActionResult`. Governance around whether an action runs is in [`decisions.md`](decisions.md) and [`permissions.md`](permissions.md).
