A comprehensive model for governing autonomous AI agents based on capability, authority, admissibility, and evidence.
Capability does not imply authorization.
Just because an agent can perform an action doesn't mean it should be allowed to.
Authorization does not imply admissibility.
Permission to act requires appropriate context, risk assessment, and oversight.
Execution requires governance.
All agent actions must be evaluated, decided, overseen, and evidenced.
Agent
Policy
Connector Event
Decision
Human Oversight
Evidence
What actions can the agent perform? From read-only to admin-level execution authority.
What data can the agent access? From public to regulated and critical operational data.
What information can the agent retain? From stateless to persistent cross-system memory.
How much human oversight is required? Human-in-loop, on-loop, or out-of-loop.
Who reviews high-risk actions? HITL requires approval, HOTL monitors, HOOTL operates autonomously.
What are the consequences of failure? From low to critical financial, regulatory, or operational impact.
Automatically calculated based on the six governance dimensions
Informational assistance, low impact, human-in-the-loop required
Defined workflows, limited authority, active oversight and approval required
Tool use, execution authority, sensitive data access, high impact potential
Open-ended operation, broad authority, critical impact, maximum oversight
Start governing your AI agents with the AGEI framework