A new research paper proposes deontic policies to govern autonomous agents that manipulate data and install software. Current engines like XACML fail to handle complex obligations, such as mandatory CISO notifications. This framework introduces formal rules for permissions and prohibitions. It provides a necessary security layer for agents operating across organizational boundaries.