Agent Authorization Terms ========================= Last updated: 2026-08-05 Legal Agent Authorization Terms ------------------------- Last updated: August 5, 2026 · Effective: August 5, 2026 These Agent Authorization Terms ("Agent Terms") govern what the AI agent provided as part of Grounds (the "Agent") may and may not do on behalf of the customer ("you" or "Customer"). They supplement the Terms of Service and the AI Data Use Policy. Capitalized terms not defined here have the meaning given in the Terms. The Agent is a feature that can perform multi-step work — drafting, negotiating, routing for signature — initiated by a human user (the "Principal") who is authorized by you to use the Service. In the v0 product the Agent operates within a single tenant; these Agent Terms are written to anticipate future multi- tenant, agent-to-agent workflows. 1. Scope of authority The Agent acts only within the scope its Principal configured for it: the workflow it was started in, the documents and matters it was granted access to, the playbook and instructions it was given, and any thresholds or guardrails the Principal set. The Agent has no standing authority outside that scope. You are responsible for what your Principals authorize the Agent to do. Configuration of the Agent is a delegation by you to your Principal, and from the Principal to the Agent, within the limits you set at the account level. 2. Outbound disclosure allowlist The Agent may disclose Customer Data outside the Grounds tenant only to the destinations on the following allowlist, and only in the course of completing the workflow it was given: • The counterparty portal that the Principal selected for the matter (or, if no portal is configured, the counterparty contact email the Principal specified). • The named signatory's email address, for delivery of e-sign envelopes initiated by the Principal. • Invited collaborators on the matter (including, for law-firm customers, attorneys and staff the firm has added to the matter) and the firm's own client portal where applicable. The Agent will not initiate agent-to-agent disclosure — i.e., it will not transmit Customer Data to another autonomous agent or third-party AI system — outside this allowlist without an explicit, recorded authorization from the Principal for that specific recipient and that specific session. 3. Audit trail Every outbound disclosure by the Agent — the recipient, the document version, the prompt context, the timestamp, and the Principal who authorized it — is written to an immutable audit log that the Customer can export at any time. Audit entries are retained for the life of the tenant and are not used for any purpose other than accountability and incident response. 4. Binding effect The Agent may communicate, negotiate, and prepare documents on the Customer's behalf. The Agent does not, by itself, bind the Customer to substantive contractual terms. A binding execution requires the explicit e-sign action of the Customer's named signatory (or a counterparty's named signatory), as described in the "Electronic signatures" section of the Terms. Internal approvals captured in the Service do not by themselves substitute for that e-sign step. 5. Approval thresholds The Customer may configure approval thresholds for the Agent at the tenant or matter level. When a threshold is set (for example, "any outbound counter-offer that changes the contract value by more than $X requires human approval before sending"), the Agent will pause and route the proposed action to a designated human approver before proceeding. The Service's default for new tenants includes a conservative dollar-value threshold that can be raised or lowered by a Customer administrator. Approvals are recorded to the audit trail. 6. Revocation The Customer or an authorized Principal may revoke the Agent's authority at any time — for a specific matter, for a specific workflow, or globally for the tenant. Revocation takes effect immediately for new actions. Actions already dispatched (e.g., emails already sent) cannot be unsent, but the Customer can use the audit log to identify and follow up on them. 7. Limits and prohibited actions The Agent will not: • Send Customer Data to recipients outside the allowlist in Section 2 without explicit Principal authorization for that recipient. • Bypass approval thresholds set by the Customer. • Disable, modify, or evade its own audit logging. • Take any action that would, on its face, violate the Acceptable Use Policy. • Initiate transactions outside the scope of the workflow it was given. 8. Liability and the Customer's responsibilities Subject to the limitations in the Terms, Grounds is responsible for the Agent operating as described in these Agent Terms. The Customer is responsible for: • Whom it authorizes as a Principal. • The instructions, playbooks, and thresholds it configures. • Verifying material AI output before relying on it. • Ensuring that use of the Agent in a particular workflow is lawful and consistent with the Customer's own contractual and ethical obligations. 9. Data use Data processed by the Agent is Customer Data and is governed by the AI Data Use Policy — including the zero-training commitment, tenant isolation, and the operational-log retention rules described there. 10. Changes We will post any material change to these Agent Terms here and notify active customer administrators at least 30 days before the change takes effect. New capabilities that broaden what the Agent can do default to off and require an administrator to enable them. 11. Contact Questions about the Agent or these Agent Terms? legal@grounds.ai.