Skip to contentThe Observability LayerSearch

Enterprise handbook · Section 4 of 30

2. Scope, impact, risk, and autonomy

2.1 Define the system boundary before rating it

Start with the business process, affected people, resources, and permitted effects. Identify every entry point and downstream consumer. Include generated content that a human may rely on, background jobs, exported files, queued actions, and child agents. A read-only tool grant does not make a workflow harmless if its recommendations determine a consequential result.

Record the intended benefit and a baseline alternative. The alternative might be a manual process, ordinary rules engine, deterministic workflow, or smaller model with constrained tools. A more complex agent design should justify its additional authority and coordination cost through observed business value.

Evidence table: Assessment dimension, Questions to answer, Artifact
Assessment dimensionQuestions to answerArtifact
Purpose and utilityWhich task is authorized? What would correct completion look like? What simpler baseline exists?Mandate and business-success rubric.
Affected peopleWho can receive wrong advice, delay, exclusion, disclosure, or adverse action?Stakeholder and impact register.
Authority and reachWhich resources, tenants, data classes, destinations, and operations can be reached?Effect-path and credential inventory.
Consequence and reversibilityWhich effects are significant, irreversible, compensable, or hard to discover?Action-class consequence register.
Dependency and scaleWhich providers, tools, reviewers, queues, and shared signals create common failures?Dependency and workload model.
Oversight and remedyWho can intervene, by when, with which evidence and correction rights?Review, escalation, and redress design.
Evidence and uncertaintyWhich outcomes can be independently checked? Which versions or data are opaque?Oracle register and limitation record.
Legal and policy contextWhich entity, geography, role, data, and decision determine applicable obligations?Scoped obligation register.

2.2 Rate risk by failure mechanism and consequence

The risk register should name a specific mechanism, affected asset or person, consequence, exposure conditions, prevention or detection control, and residual uncertainty. A label such as hallucination risk is too broad to drive implementation. Wrong currency conversion in a draft and a fabricated payment-success claim need different controls.

A proposed qualitative assessment can consider severity, opportunity for exposure, propagation, detectability, reversibility, and uncertainty. Do not manufacture a numerical probability when the available data only supports a qualitative judgment. Do not let a low-likelihood guess cancel an intolerable consequence.

Evidence table: Illustrative failure, Consequence, Prevention or reduction, Independent observation
Illustrative failureConsequencePrevention or reductionIndependent observation
Retrieved instructions redirect a payment beneficiary.Unauthorized transfer.Action-bound approval and resource-side authorization.Beneficiary, amount, grant, approval, and ledger receipt.
A citation describes the wrong reporting period.Misleading advisor research.Entity/period validation and deterministic calculation.Source document and independently checked answer rubric.
A child resets its spending budget on restart.Aggregate exposure exceeds mandate.External global budget and lineage.Shared ledger and restart/child negative tests.
Repeated document requests exclude a customer group.Uneven access, delay, or possible rights harm.Stage-level outcome review and alternative designs.Eligible cohort, burden, completion, and remedy records.
A monitor flags risk after a commit.Detection without successful prevention.Gate timing, enforceable holds, tested failure policy.Effective halt timestamp and external effect state.

2.3 Autonomy is a permission decision by action class

The following tiers are a proposed teaching and policy aid, not a universal industry taxonomy or legal classification. An enterprise can approve different tiers for different actions within the same workflow. A research assistant may autonomously retrieve public information while requiring review before sending a client-facing summary.

Evidence table: Proposed tier, Permitted behavior, Example, Minimum operating condition
Proposed tierPermitted behaviorExampleMinimum operating condition
A0: AnalyzeProduce observations without business-system changes.Internal research or invoice comparison.Scoped data access, factual evaluation, and role limits.
A1: PrepareCreate a draft or reversible staging artifact for review.Draft reply or proposed reconciliation.Clearly marked draft state, scoped storage, no hidden downstream commit.
A2: Execute after approvalExecute a specific approved action or explicitly defined batch.Approved beneficiary and amount.Action-bound consent, current authorization, expiry, independent result check.
A3: Execute within boundsSelect and execute predefined action classes under enforced limits.Resolve a bounded class of internal tickets.Tested invariants, global budgets, timely intervention, reconciliation, and staffed escalation.
A4: Adapt operating componentsModify reusable skills, routing, or memory within a separately approved change process.Propose a new reconciliation skill for gated deployment.Integrity, affected-interaction testing, evidence expiry, and independent release authorization.
Figure 2. Autonomy requires different evidence for different effects

Open figure at full size ↗

Figure 2. Autonomy requires different evidence for different effects

Figure 2. Proposed decision aid. The displayed control requirements increase with permitted behavior. They are policy examples and contain no measured capability or risk scores. Higher tiers do not authorize the agent to change the governance policy.

Treat irreversible disclosures, payments, privilege changes, covered decisions, and externally published content as distinct effect classes. State which require approval and which cannot be delegated. A control failure, unresolved evidence gap, or reviewer-capacity failure should reduce permitted authority until the relevant claim is re-established.

2.4 Establish an exception process that expires

An exception should identify the unmet control, business need, consequence, compensating measure, accountable approver, scope, expiry, and closure evidence. It does not turn an untested mechanism into an effective control. An emergency operating decision should specify how new authority is bounded and how affected evidence will be restored.