Governance & Trust

2026

Autonomy and Decision Rights

Define what an agent may observe, propose, prepare, execute and approve—and where a human must intervene.

The phrase “human in the loop” is too vague for a transformation program. A person can be copied on an output without exercising meaningful control.

A practical autonomy ladder

Observe

The agent retrieves, classifies and monitors information but does not change project records.

Recommend

The agent analyzes options and proposes an action. A person decides and executes.

Prepare

The agent creates a transaction, configuration instruction or workflow package, but a person approves execution.

Execute within policy

The agent performs pre-authorized, reversible actions within explicit thresholds. Exceptions stop or escalate.

Coordinate bounded workflows

The agent sequences multiple approved actions and agents, while material decisions and exceptions remain human.

“Approve its own work” is deliberately absent.

Define decision rights precisely

For each activity, document who:

  • initiates the work.
  • provides context.
  • prepares the recommendation.
  • challenges the evidence.
  • decides.
  • executes.
  • verifies the outcome.
  • accepts residual risk.

This can be expressed as a human–agent responsibility matrix rather than forcing agents into a conventional RACI.

Match control to impact

Consider financial, operational, regulatory, security and reputational impact; reversibility; time sensitivity; uncertainty; and the availability of independent verification.

A low-impact, fully reversible update can operate with automated guardrails. A go-live recommendation affecting statutory close should remain advisory and subject to accountable review.

Prevent approval theatre

Human review is ineffective when the reviewer lacks time, evidence or authority. The interface should show the decision, relevant sources, uncertainty, alternatives and consequences—not ask someone to click “approve” beneath a confident paragraph.