Action is what the agent attempted. It is a request to a provider, with its idempotency key. The agent performs it with its own credentials. Provely never performs the action.

Example: POST /v1/refunds with Idempotency-Key: op_01J.... The contract records the canonical effect, money.refund, and the provider operation.