The platform
Three planes. Eleven surfaces.
One governed estate.
Governing autonomy is not one feature. It is a stack. Three planes, read left to right: know what can act, govern the action, prove it held. Eleven surfaces sit across them, and every surface keys off the one before it. Nothing downstream is trustworthy if the ground is not.
Plane 01 · 3 surfaces
Provenance
Know what can act
Plane 02 · 4 surfaces
Runtime
Govern the action
Plane 03 · 4 surfaces
Assurance
Prove it held
A request enters at Provenance, is checked in the Runtime, and lands in Assurance as evidence. Open any surface to jump to its section.
Authority, declared
Five rungs of what a system may do.
The real surface of autonomy is not what an agent is doing now, it is what it is allowed to do at any moment. Every step up the ladder is declared and recorded, never a default, and each rung attaches its own guardrail.
The Authority Ladder
Declared, never default
- 1
Read only
Retrieve and summarise. Nothing it touches changes.
Data scope and sensitivity class
- 2
Suggest
Propose an action. A person commits it.
Every commit is human
- 3
Act within reversible bounds
Commit actions that can be undone.
Reversibility and a blast radius cap
- 4
Consequential action
Commit actions that cannot be taken back.
A named human approves before commit
- 5
Self directed inside a mandate
Choose its own steps toward a stated goal.
Mandate bounds, kill switch, standing review
Drift up the ladder is the failure agent governance exists to prevent. The Registry records the rung, the Control Plane enforces it.
The language of the category
The words the site owns.
Governance for the agentic enterprise needed a vocabulary, so we built one. These terms are precise, they are ours, and they do the arguing so the copy can stay short.
The Seam
Where data becomes a decision.
The join between the data estate and the AI estate. Both run well alone. The unmanaged place between them is where AI failures actually happen, and today no one owns it.
The Estate
Everything that can read data or act.
Datasets, models, copilots, agents, service accounts, and third parties. If it can read or act, it is in the estate, and it is in scope.
The Consequence Gap
The time between an action and its effect.
Old controls all depended on this gap being wide enough for a person to step in. Autonomy closes it to zero, which is why controls that review after the fact stop working.
Standing Authority
What an agent may do while idle.
The real surface of autonomy is not what an agent is doing now, it is what it is allowed to do at any moment. Standing authority is the access that sits there waiting to be used or abused.
The Authority Ladder
Five rungs of what a system may do.
From read only, to suggest, to act within reversible bounds, to consequential action, to self directed inside a mandate. Every step up is declared and recorded, never a default.
Shadow Autonomy
Tools quietly gaining the power to act.
A copilot that starts writing back. A workflow that starts deciding. Authority no one granted on purpose, accumulating faster than any audit can catch.
The Attribution Triple
Which agent, for whom, under what authority.
Every action answers all three or it does not commit. It is the minimum record that makes an autonomous action accountable to a person and a policy.
Blast Radius
How far one confused agent can reach.
Least privilege is not hygiene here. It is the containment boundary that decides whether one compromised agent touches one account or ten thousand.
The Trust Gate
Nothing reaches a model until it clears.
A single checkpoint between the data estate and any model, asking three questions: is it sensitive, is it sound, do we know where it came from.
The Kill Switch
Stop one action, or everything, at once.
Immediate, total, and tested. An agent that cannot be stopped is an agent that cannot be deployed. Not a feature. The precondition for deployment.
Living Evidence
Proof that writes itself.
The audit trail is a byproduct of governed execution, current the moment anyone asks. Not a binder assembled for an exam, and never stale.
Proof on Demand
The exam becomes a query.
Ask the system a question a regulator would ask, and the record answers with the dossier and the evidence attached.
The Governance Graph
The live map that ties it all together.
Every dataset, model, agent, control, and rule, connected. Pull one node and see everything it touches. Impact analysis becomes a gesture instead of a project.
The Examination Surface
Every question an examiner can ask.
The full set of questions a regulator could put to you, and whether you can answer each one right now. Fiducia shrinks the unanswered part of that surface to nothing.
Walk the stack on your own estate.
A 30 minute working session: pick a plane, pick a surface, and see it against a control or an agent you already run.