Trust and autonomy
Five levels deciding how much runs without a person — with limits that no level can override.
AI Employee → Trust & Autonomy.
| Level | Means |
|---|---|
| 0 Observe | Suggests only. Nothing runs. |
| 1 Approve all | Every task waits for a person. |
| 2 Approve risky | Routine work runs; anything material waits. |
| 3 Autonomous with caps | Runs within materiality limits. |
| 4 Full | Runs everything its role allows. |
Every capability declares the trust it needs. Read-only analysis needs 0; categorising needs 1; ledger writes need 2; paying a bill or closing a period needs 3; running payroll or filing a return needs 4.
Reopening a period outranks closing one — undoing a sign-off is a bigger act than making one.
Three things no trust level can override:
- Anything irreversible always needs a person. See Work that cannot be undone.
- A material amount needs the role your materiality rules name, whatever the level says.
- The preparer is never the approver, enforced by user id at the moment of approval. A role check does not catch someone approving their own work.
An unknown capability defaults to needing approval — fail closed, so something added later cannot quietly inherit autonomy.