Agent governance
The question
How much authority should an AI agent have?
Hypothesis
Useful autonomy requires explicit boundaries for code, infrastructure, production, data, money movement, and irreversible actions.
Method
Draft capability tiers for representative agent tasks, test enforcement through permissions and review gates, and record violations and near misses.
Early signal
Three boundaries now enforced by machines, not policy docs, in production systems: (1) deploys refuse to restart the live app when the build or generated client fails verification — the gate aborts leaving production untouched; (2) every cost-ingestion event carries an idempotency key, so retries can never double-count spend; (3) every deployment snapshots the previous release (last five retained) before mutating anything. The pattern so far: boundaries that live in code hold; boundaries that live in docs get bypassed under time pressure.
Outcome
Partial: enforcement patterns proven in production deploys and ingestion; capability tiers for broader agent tasks still being drafted. This entry is ACTIVE.