Governance & Trust
2026Autonomy and Decision Rights
Define what an agent may observe, propose, prepare, execute and approve—and where a human must intervene.
The phrase “human in the loop” is too vague for a transformation program. A person can be copied on an output without exercising meaningful control.
A practical autonomy ladder
Observe
The agent retrieves, classifies and monitors information but does not change project records.
Recommend
The agent analyzes options and proposes an action. A person decides and executes.
Prepare
The agent creates a transaction, configuration instruction or workflow package, but a person approves execution.
Execute within policy
The agent performs pre-authorized, reversible actions within explicit thresholds. Exceptions stop or escalate.
Coordinate bounded workflows
The agent sequences multiple approved actions and agents, while material decisions and exceptions remain human.
“Approve its own work” is deliberately absent.
Define decision rights precisely
For each activity, document who:
- initiates the work.
- provides context.
- prepares the recommendation.
- challenges the evidence.
- decides.
- executes.
- verifies the outcome.
- accepts residual risk.
This can be expressed as a human–agent responsibility matrix rather than forcing agents into a conventional RACI.
Match control to impact
Consider financial, operational, regulatory, security and reputational impact; reversibility; time sensitivity; uncertainty; and the availability of independent verification.
A low-impact, fully reversible update can operate with automated guardrails. A go-live recommendation affecting statutory close should remain advisory and subject to accountable review.
Prevent approval theatre
Human review is ineffective when the reviewer lacks time, evidence or authority. The interface should show the decision, relevant sources, uncertainty, alternatives and consequences—not ask someone to click “approve” beneath a confident paragraph.