A team “integrates” a model and means they put an API key in a secret store. The invoice has a model name. Slack has a bot. Nobody can say who owns the prompt, who owns the tools, or whose name a bad answer will carry. That is a subscription. It is not an integration.
Four seats
Operating design is four named seats. If any is empty, stop saying integrated.
Model. Who chose this model, who can change it, and who pays when it is wrong. A default in a vendor console is not an owner.
Prompt and charter. Who writes the standing instruction, and where it lives. A prompt in six chats is folklore. The charter says what the worker does. The override doctrine says what it must refuse: spending above a ceiling, speaking as the company, changing production data, closing a judgment you still own.
Tools. What the model may see, change, send, or delete. MCP is the contract for one server. The operating question is who approved that contract, and who can revoke it at 17:00.
Review. Who can fail the output against written criteria. A human in the loop is that person. A glance at a dashboard is not a loop.
You would not ship a payment integration without those four. A language model that can mail, spend, or open a pull request is a payment integration with better prose.
The worker definition sits next door. What is an AI agent? is three tests and a seven-field charter. This page asks who sits in the seats after you decided it is a worker.
An empty-seat week
Monday: someone pastes a key into the host. Tuesday: a prompt lives in three chats and a Notion page. Wednesday: the mail tool can send. Thursday: a customer gets a draft no reviewer saw. Friday: nobody knows whose name is on it.
That week had a model. It did not have four names. The repair is not a better wrapper. Write the four names. Put the standing prompt in one file. Revoke send until the first ten calls have a reviewer. If coordination is already failing, adding a second unowned model makes the board worse, not smarter.
What STACK is not doing on this page
STACK is the five-layer map for the repo: structure, toolchain, agent configuration, connection, knowledge and quality. The Agentic Codebase is the live book. Version the artifacts like the app.
This page is earlier and smaller. Before you argue about folders, fill the seats. A perfectly versioned prompt with no reviewer is still an unowned outcome.
MCP is how a step touches the building: visibility, mutation, log. It is not who signed for the keys.
The protocol that sits on the seats
The Delegated Mind treats delegation as governance, not tooling. The protocol is PROVISO: pause, retain agency, observe, verify, integrate, own. The book is in production. It is not for sale. The one-page charter from that manuscript is already the right artifact: what agents may do, what they may never do, how output is verified, who signs off, whose name it carries.
If you cannot write that page, you do not have an integration. You have a faster paste.
The Human-in-the-Loop Life is the personal side. Human in the loop is not a property of the software. It is a question about you: where you stand in the cycle, at what level, and whether you are actually there. That book is an early draft. Use the question anyway. If approval has become the motion you make on the way to merge, the loop is decorative.
A twelve-minute audit
Pick one live model call in the company.
| Seat | Name, not role | File or log that proves it | Last time this seat actually acted |
|---|---|---|---|
| Model | |||
| Prompt / charter | |||
| Tools | |||
| Review |
Then write the one forbidden action, and whose name last week’s worst answer would have carried.
Blank lines are the integration. Fill them or take the tools away. The model name on the invoice will not do it.