core-concept · Security & governance · maturing · Reviewed

Risk-tiered autonomy

The practice of classifying an agent by impact, data sensitivity, action scope, and reversibility, then binding that tier to maximum autonomy, required controls, approval authorities, and monitoring depth.

Definition

The practice of classifying an agent by impact, data sensitivity, action scope, and reversibility, then binding that tier to maximum autonomy, required controls, approval authorities, and monitoring depth. Autonomy is an evidence-backed risk budget, not a feature toggle.

Risk-tiering is established; consistent mappings from agent capability to permitted autonomy are still evolving.

Why it matters

Autonomy is an evidence-backed risk budget, not a feature toggle.

The operating shift is from “Automation on or off” to “Graduated, bounded decision authority.”

System anatomy

Practice 1
Classify risk before architecture and build
Practice 2
Separate assistive, read-only, transactional, and consequential authority
Practice 3
Reclassify when tools, data, users, or impacts change

Important distinctions

Automation on or off
This concept moves the engineering system toward graduated, bounded decision authority.

Implementation signals

  • Classify risk before architecture and build
  • Separate assistive, read-only, transactional, and consequential authority
  • Reclassify when tools, data, users, or impacts change

Failure modes

  • A low-risk label surviving material scope expansion
  • One checklist applied to both drafting and consequential action

Sources and further study

  1. Microsoft Agentic Center of Excellence — Govern agents by risk

    Current enterprise guidance for matching review depth, autonomy limits, release gates, logging, and incident planning to agent risk.

    Use in this library: Official guidance. Guidance describes recommended practice; citation does not prove that a control is implemented or effective in a particular environment.

    guidance · guidance · Published 2026-07-14
  2. NIST — Artificial Intelligence Risk Management Framework 1.0

    A consensus-based foundation for governing, mapping, measuring, and managing AI risk according to context, impact, and organizational priorities.

    Use in this library: Standard or protocol. A specification defines an interface or control pattern; conformance alone does not establish authorization, security, or fitness for a use case.

    standard · standard · Published 2023-01-26
  3. NIST NCCoE — Identity and Authority for Software Agents concept paper

    A concept paper exploring how established identity and authorization practices can apply to software and AI agents.

    Use in this library: Official guidance. Guidance describes recommended practice; citation does not prove that a control is implemented or effective in a particular environment.

    guidance · guidance · Published 2026-02-05