Foundations

Authority

Five layers, evaluated per action, never collapsed into “autonomy 80%”. A credential is not permission. A click is not permission beyond the clicker’s role. An approval is for one version.

Five layers

LayerQuestionExample
CapabilityCan the adapter technically do it?The API credential can write inventory
PermissionDoes policy allow this role?Operations may edit mappings; finance may not
DelegationIs it inside what this Case delegated?“Check stock” delegates reading, not editing
ApprovalDid the required person approve this version?Approved mapping rule v3 for Shopify and Amazon
ValidityIs all of that still true at execution?The mapping changed since approval: re-check

The approval path is separate

An agent writing “human approved” proves nothing. The application must know who reviewed which version, through a path the agent cannot author (INV-13). Approval binds to targets, recipients, amounts and scope. A material change invalidates it; an immaterial one (a typo in a label) does not force re-approval (INV-04).

The allowed action set

Every control in a Representation Plan comes from the allowed action set evaluated at plan time. It is not a standing right. At the moment of execution the action is re-validated, and a stale control leads to a re-check that says what changed, never to an execution against the old state (INV-03).

const check = validateAtExecution(state, 'p-mapping', 'v3');
// { ok: false, reasons: ['The proposal changed from v3 to v4.', 'Authority is stale.'] }

A disallowed control is not silently hidden when the plan lists it. It is rendered as explained and non-operable, so a person can see what is not possible and why.

Risk is a vector

Money · privacy exposure · blast radius (how many objects) · reversibility · downstream propagation · detectability · recovery cost · time sensitivity · evidence gap · authority ambiguity. Policy combines them, but no total score may cancel a hard prohibition. Risk and authority are never colour tokens: policy decides, presentation only presents.

Consequence-proportional disclosure

Enough for the judgment, not a bigger card. For a change that matters: affected objects, preserved objects, scope, reversibility, notifications, alternatives and verification conditions. For small, reversible, delegated work: no ceremony at all, so attention is left for the moments that need it. Pattern: disclosure

Human judgment points

Not “the agent feels unsure”. A judgment point is one of these:

The person decides a concrete choice with stated evidence and consequences, never “do you trust the AI?”.