AI Agent Autonomy: Earned Scope, Explicit Limits
Useful autonomy starts with a defined action class, a human-granted envelope, and evidence. The gate remains in place as routine work needs less supervision.
Published August 14, 2026
The objective is useful work that requires less routine supervision. Authority is set per action class, per company. Permission to edit a draft says nothing about permission to publish it or spend money.
The progression
- Draft: prepare the artifact; nothing executes.
- Shadow: record the proposed action and expected outcome without an external write.
- Sandbox: exercise the lifecycle against a sandbox provider.
- Autonomous inside an envelope: policy or a watchdog resolves the gate within explicitly granted limits.
- Widened envelope: a human grants more scope after reviewing the evidence.
- Human-resolved: a person, or two people where required, resolves each decision in the class.
Human resolution can be the right ongoing arrangement for difficult decisions. Routine classes need not wait there indefinitely. At installation, each class starts where its risk, evidence, and supported implementation justify.
What an authority envelope means
An envelope names the actions allowed, their limits, duration, and conditions. The system checks it at the one gate. Money movement is denied by default; any exception needs an explicit human grant within provider, legal, and platform constraints. A proposal credential alone cannot approve or execute.
Evidence earns a review, not automatic permission
The decision record separates execution correctness, judgment quality, and governance quality. Outcome confidence and attribution limits travel with the grade. Strong evidence can support a promotion proposal; only an authorized human can expand the grant.
The product design calls for scope to contract when authority checks fail, evidence becomes stale, or grades deteriorate. An agent cannot counter that by declaring itself successful.
Current availability
This is the Powered by Figaro model ratified September 14, 2026. It sets the product direction; it does not assert that every action class is implemented or proven in production. The existing native Figaro operator system uses human approval for consequential writes. Each managed installation must establish its actual coverage.
Questions founders ask
- Can an agent expand its own authority?
- No. Results supply evidence for a promotion; an authorized human must grant any wider scope. Action classes and limits do not expand through learning alone.
- Does autonomy remove the approval gate?
- No. There is one resolution boundary. Human, policy, and watchdog are decider classes at that boundary, with explicit authority; they are not alternative gates.