AI capability

What an agent may do, decided by you

Autonomy is not a slider from off to on. It is a specific grant: this workflow, in this entity, below this amount, when confidence exceeds this threshold, with this escalation when it does not. Every agent in the system starts at observe and moves only when you move it.

Level 0ReadAnswer questions from your data. No approval needed.
Level 1DraftPrepare the action. A person reviews and commits it.
Level 2Execute within policyAct automatically inside rules a controller wrote.
Level 3Approval requiredHeld at a gate until a named approver signs.
Level 4RestrictedOnly specific human roles may ever execute.
Five levels, granted per workflowStarts at observe, alwaysSome things stay at never

What it does

Six things, specifically.

Observe

The agent watches and reports. It writes nothing. This is where every agent starts and where several stay for the first few weeks while you read what it would have done.

Draft

It prepares work — coded bills, matched payments, drafted journals — that sits in a queue until a person releases it. Nothing reaches the ledger without that release.

Propose

It puts a specific recommendation in front of a named approver with the reasoning attached, and the approver accepts, edits, or rejects. The rejection is training data.

Execute within limits

It acts without a person, inside the boundary you set — this workflow, this entity, under this amount, above this confidence. Outside any of those, it escalates rather than proceeding.

Never

A fixed set of actions no agent may take at any configuration: releasing payment, changing vendor banking, granting permissions, closing a period, or filing anything statutory.

Movement is deliberate

Authority is raised by a person, recorded with who raised it and when, and can be lowered instantly. It does not drift upward on the basis of good performance.

Why a single autonomy setting fails

The instinct is to describe an agent as more or less autonomous. It does not survive contact with a real finance function, because the same agent should be trusted very differently depending on what it is doing and where.

Coding a recurring $400 utility bill from a vendor with two hundred prior identical bills is a different act from coding a $60,000 invoice from a new supplier with an ambiguous description, and both are the accounts payable agent. Authority granted per workflow, per entity, and per threshold is the minimum granularity that matches how the work actually differs.

Autonomy is not a property of an agent. It is a property of an agent doing a particular thing, in a particular place, below a particular amount.

Everything starts at observe

An agent’s first weeks are spent producing a shadow record: what it would have done, beside what your team actually did. That comparison is the only honest basis for deciding whether to raise its authority, and it costs you nothing to run.

It is also where the surprises surface. The disagreement rate is rarely uniform — it concentrates in one vendor, one account, or one entity, and that concentration usually points at a data or policy problem rather than a model problem.

Confidence is a threshold, not a display

Every automated decision carries a calibrated confidence, and the threshold is a grant condition rather than a badge on a screen. Below it, the agent escalates with its reasoning and its alternatives; above it, it proceeds within the other limits.

Calibration is checked against outcomes rather than asserted. An agent claiming 95% confidence should be right about 95% of the time, and where it is not, the threshold moves rather than the claim.

Lowering is instant

Raising authority is deliberate and recorded. Lowering it is immediate and needs no justification — a single control that returns an agent to draft, applied at the workflow, entity, or agent level.

The asymmetry is intentional. A control you can only exercise through a process is a control you will not exercise at the moment you most want to.

Limits

Where it does not help.

Every capability page on this site carries one of these, because a feature described without its boundaries is a claim rather than a description.

The ceiling is not configurable

Payment release, vendor banking, permission grants, period close, and statutory filing stay at never regardless of what a customer would prefer. That is the one decision we take away.

Higher authority needs better data

An agent executing within limits on poor-quality inputs escalates constantly, which is worse than leaving it at draft. We will say when the data is not ready.

It cannot resolve who approves

If your organisation has not decided who authorises what above a given amount, the authority model has nothing to encode. That decision precedes configuration.

Questions

What people ask.

Can we start fully automated?
You can, and we recommend against it. The observe period costs nothing and tells you where the disagreements concentrate before they become postings.
What can never be automated?
Payment release, vendor banking changes, permission grants, period close, and statutory filing. Those are fixed rather than configurable.
Does authority increase automatically?
No. It moves only when a person moves it, and the change is recorded with who and when. Good performance is evidence for a decision, not the decision.
How fast can we pull it back?
Immediately, at agent, workflow, or entity level, with no justification required. Draft work already queued stays queued for a person.
Is confidence meaningful?
It is calibrated against outcomes rather than asserted. Where an agent’s stated confidence does not match its accuracy, the threshold moves.

Decide the first grant deliberately.

Tell us the workflow. We will tell you what authority it needs and where the ceiling should sit.