Autonomy ladder
Separate what an AI may observe, propose, prepare, and execute; cap autonomy by action risk; earn narrower authority with measured evidence; and reduce it automatically when quality regresses.
Autonomy is resolved per action, not granted to an agent as a permanent personality trait.
Levels
| Level | Agent may | Example | Oversight |
|---|---|---|---|
A0 · Observe |
Classify in shadow; no operational output. | Compare predicted case type with human outcome. | Offline evaluation only. |
A1 · Assist |
Summarize and recommend. | Harbor case summary with cited facts. | Human chooses all actions. |
A2 · Prepare |
Build a typed draft or action request. | Draft a reminder or two-part promise. | Required reviewer/action approval before effect. |
A3 · Execute bounded |
Execute explicitly allowlisted, low-risk actions inside policy. | Apply an internal case label or send a qualified low-risk reminder. | Post-action sampling, live compliance gate, instant suppression. |
Money movement, contract changes, sensitive disclosures, and high-impact restrictions can remain approval-bound even when an agent has A3 authority for another action.
Effective level
requested level
∩ tenant ceiling
∩ action ceiling
∩ channel/jurisdiction ceiling
∩ model + prompt qualification
∩ current quality-earned level
∩ live suppression state
= effective level
The lowest applicable ceiling wins.
Promotion evidence
Promotion requires a version-specific evaluation cohort and approved thresholds for:
- factual precision and citation coverage;
- human acceptance and material-edit rate;
- false-negative regulated-signal rate;
- compliance blocks and attempted prohibited tool calls;
- action reversal and customer complaint rate;
- subgroup performance and fair-lending/fair-servicing review;
- operational latency, availability, and cost.
A global average cannot hide failure on a small but high-risk case type.
Shadow and canary
Automatic reduction
Regression can reduce effective autonomy immediately. Triggers include a critical review finding, compliance-block spike, grounded-fact failure, prohibited-tool attempt, drift beyond approved bounds, or kill switch. Restoration requires a recorded review; an agent never raises its own level or evaluates its own promotion.