rotascale authority and evidence for AI agents See the demo

Frameworks — trust maturity

Most organisations are at one and believe they are at three.

Five levels. The jump that matters is not the first or the last — it is three to four, where evidence stops being something you produce for yourself and starts being something somebody else can check.

LevelWhat existsThe question it cannot answer
1 · Unrecorded Agents run. Logs exist somewhere, in whatever shape the framework emitted. What did this agent do, and on whose behalf?
2 · Observed Traces, token spend, latency. A dashboard. Was it allowed to?
3 · Bounded Authority stated in advance. Refusals happen and are recorded. Can somebody who does not trust us confirm any of this?
4 · Evidenced Records sequenced, sealed and independently verifiable. Gaps detectable rather than merely suspicious. Does it hold across several regimes at once?
5 · Governed The regime resolved per decision and sealed with it; obligations scored against what currently applies; controls tested adversarially and the failures published.

The self-assessment error is almost always the same: an organisation with a good observability stack reads level two as level three, because the dashboard shows refusals the application made. A refusal your own code chose to make is a feature, not a control — the control is the one your code could not have avoided.

Level five is not a product you buy. Levels three and four are largely mechanical and RotaGrant supplies most of the machinery. Five needs decisions only your organisation can make — which regimes you are under, what an incident is, who signs for what — and any vendor selling it as an outcome is selling you a feeling.