Skip to content

Concepts

Autonomy tiers

How much an agent may do without a person is earned on evidence, one rung at a time, with sign-off from the people who carry the risk. An agent nobody has graded is an intern.

Mandates say what an agent may do. Its tier says how much of that it may do alone. A tier can only turn an allow into a question; it never turns a question or a refusal into an allow.

#The four tiers

TierSaysPays alone up toReleases data aloneRecords per action, alone / at most
internPrepares the work. A person signs off every payment, data release and outside actionnothingno0 / 1,000
juniorHandles small, routine work alone. Bigger payments and any data release go to a person£50no100 / 10,000
seniorTrusted with everyday payments and releases inside its mandates. Large ones go to a person£1,000yes1,000 / 100,000
principalWorks inside its mandates without routine sign-off. Its mandates are its only limitsno lineyesno line

The money lines are held in pounds and converted for other currencies at a reference rate; a currency with no reference rate is checked by a person at every tier below principal. Records above the “alone” figure are asked about; above the “at most” figure they are refused (volume_hard_limit).

New agents start at the workspace’s starting tier, intern unless an owner chose junior on the record (with colleagues in the workspace, a second owner confirms). A service token registering agents can never ask for more.

#Earning the next rung

Promotion is one step at a time, and only when the evidence is there:

ToClean decisionsDays of historyDays without an incidentSign-offs
junior2077business
senior1503030business, security
principal1,0009090business, security, legal

An agent refused more than 10% of the time since its last change of tier is not ready: an agent that is refused often is probing, or doing the wrong job. The console shows exactly what is missing (“12 more clean decisions; sign-off from security”).

#Separation of duties

  • Nobody promotes an agent that acts for them.
  • Whoever signed off a promotion does not also make it.
  • Auditors check sign-offs; they do not give them.
  • A sign-off is for the promotion in front of it, and lapses after 30 days.

#Break-glass

An owner can promote without the evidence, with a reason of at least a sentence. With anyone else in the workspace it is a proposal a different owner confirms within seven days, and no agent is overridden twice in a week. It is still one rung: break-glass is for a rung, not the ladder.

#Losing it

Demotion needs no evidence and takes effect at once. It also happens without anyone choosing it:

  • an access profile not recertified by its due date demotes the agent to intern and freezes it;
  • a review verdict of incident freezes the agent under an incident hold.

#Standing

Every agent carries its standing: the sponsor who answers for it, its purpose in a sentence, the kill owner who may stop it, and when its assignment ends (at most 366 days, then someone renews it). The people named must be members of the workspace.

Shell
curl -X PATCH "https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/agents/agt_4f2c91a7/standing" \
  -H "cookie: __Host-sid=$IMMISCIBLE_SESSION" -H "x-immiscible-csrf: 1" \
  -H "content-type: application/json" \
  -d '{ "sponsor": "cfo@acme.example", "purpose": "Pays approved supplier invoices", "killOwner": "secops@acme.example", "assignmentEndsAt": "2027-01-31T00:00:00Z" }'

Every change of standing and tier is a record in the evidence ledger: who sponsored the agent, who signed off its promotion and on what evidence, who demoted it and why. A promotion is a decision about risk, so it leaves the same kind of evidence a payment does.

#API

MethodPath
GET/api/w/:wid/agents/:aid/standingtier, readiness, sign-offs
PATCH/api/w/:wid/agents/:aid/standingsponsor, purpose, kill owner, assignment
POST/api/w/:wid/agents/:aid/signoffssign off a promotion
POST/api/w/:wid/agents/:aid/tierpromote or demote
GET/api/w/:wid/governance/scorecardthe signed zero trust scorecard