Separating Capability from Permission: A Governance Framework for Agentic AI Autonomy Levels
What an agent can do and what it's allowed to do are two different axes, and most teams scale them together without deciding to.
Interesting idea from Zheng and colleagues. Pull capability and permission apart.
An agent's capability and its permission are two different axes, and people blur them constantly. The paper maps five autonomy tiers against control, reversibility, and accountability.
Best line is almost a throwaway: auto-scaling an agent's permissions as its capability grows is an accountability call nobody's actually making on purpose.
Separating Capability from Permission: A Governance Framework for Agentic AI Autonomy Levels
A two-axis framework separating what an agent is technically capable of from what it is authorized to do, mapping five autonomy tiers against control, reversibility, and accountability.