rotascale authority and evidence for AI agents See the demo

Frameworks — bounded autonomy

A boundary nothing enforces is a diagram.

The conventional goal is full automation. We think that is wrong: the best outcomes come from systems where autonomy expands and contracts with demonstrated trust. We argued that for years in advisory work, and then had to admit the argument was incomplete.

What was missing from the framework

Every organisation we presented this to agreed with it. Almost none could implement it, and the reason was always the same: there was nowhere to put the boundary. Autonomy was a property of a prompt, a config file, or a convention in somebody's head — so "expand it as trust is demonstrated" meant editing something no auditor could later inspect.

A boundary that lives in a slide is a description of intent. A boundary that refuses an action and records the refusal is a control.

The boundary needs an object
Something an agent holds, that says what it may do, up to what value, until when, and under what conditions. A grant, signed for by a named person, rather than a role or a key.
Expansion needs a ratchet
The enforcement ladder — observe, shadow, canary, enforce — where a grant climbs as its record justifies it. And a delegated grant may climb but never descend, because "we lowered the bar for a subordinate agent" is the failure mode this framework exists to prevent.
Trust needs to be demonstrated to something
A week in observe produces a report of what enforcement would have refused, over real traffic. That is demonstrated trust with a denominator, rather than an absence of incidents somebody interprets as safety.
Contraction has to be instant and total
Revocation reaching a whole delegation tree, and the question was anything allowed afterwards answered rather than assumed.

The uncomfortable half

Bounded autonomy is usually presented as a way to increase autonomy safely, and that is the half people like. The other half is that a system which has not earned expansion should not get it, and the most common finding in our advisory work was a governance layer that observed everything, refused nothing, and was presented internally as though it were enforcement. Every screen in RotaGrant that lists a grant in observe says it refuses nothing, for that reason.