Foundations
Authority
Five layers, evaluated per action, never collapsed into “autonomy 80%”. A credential is not permission. A click is not permission beyond the clicker’s role. An approval is for one version.
Five layers
| Layer | Question | Example |
|---|---|---|
| Capability | Can the adapter technically do it? | The API credential can write inventory |
| Permission | Does policy allow this role? | Operations may edit mappings; finance may not |
| Delegation | Is it inside what this Case delegated? | “Check stock” delegates reading, not editing |
| Approval | Did the required person approve this version? | Approved mapping rule v3 for Shopify and Amazon |
| Validity | Is all of that still true at execution? | The mapping changed since approval: re-check |
The approval path is separate
An agent writing “human approved” proves nothing. The application must know who reviewed which version, through a path the agent cannot author (INV-13). Approval binds to targets, recipients, amounts and scope. A material change invalidates it; an immaterial one (a typo in a label) does not force re-approval (INV-04).
The allowed action set
Every control in a Representation Plan comes from the allowed action set evaluated at plan time. It is not a standing right. At the moment of execution the action is re-validated, and a stale control leads to a re-check that says what changed, never to an execution against the old state (INV-03).
const check = validateAtExecution(state, 'p-mapping', 'v3');
// { ok: false, reasons: ['The proposal changed from v3 to v4.', 'Authority is stale.'] }
A disallowed control is not silently hidden when the plan lists it. It is rendered as explained and non-operable, so a person can see what is not possible and why.
Risk is a vector
Money · privacy exposure · blast radius (how many objects) · reversibility · downstream propagation · detectability · recovery cost · time sensitivity · evidence gap · authority ambiguity. Policy combines them, but no total score may cancel a hard prohibition. Risk and authority are never colour tokens: policy decides, presentation only presents.
Consequence-proportional disclosure
Enough for the judgment, not a bigger card. For a change that matters: affected objects, preserved objects, scope, reversibility, notifications, alternatives and verification conditions. For small, reversible, delegated work: no ceremony at all, so attention is left for the moments that need it. Pattern: disclosure
Human judgment points
Not “the agent feels unsure”. A judgment point is one of these:
- a new interpretation changes what an action means,
- an evidence conflict remains,
- the action leaves the delegated scope,
- an irreversible effect is about to start,
- recovery needs a business decision.
The person decides a concrete choice with stated evidence and consequences, never “do you trust the AI?”.