Control Design
An agent's autonomy isn't a switch — it's a dial. Approval gates, autonomy levels, escalation paths, kill switches: the control design that makes autonomy shippable.
▶ Watch this reelWhat you'll learn
- Approval gates
- Autonomy levels
- Escalation paths
- Kill switch, rollback & audit
Remember this
- Approval gates trigger on consequences and parameters, render what-not-which previews, batch intelligently, and stay rare enough to be read
- Autonomy is a per-dimension dial — suggest → recommend → act → act-and-report — earned through measured reliability and demoted on regression
- Escalations carry complete packages and feed the learning loop; kill switches are independent, drilled, and paired with rollback-by-design
Approval gates
- Consequence + parameter aware · show WHAT (rendered preview/diff) not which tool · batch as consolidated diffs · rare enough to be read.
Autonomy levels
- Suggest → recommend → act (bounded) → act-and-report.
- Per-dimension, per-user; earned via measured success, auto-demoted on regression; versioned config artifact.
Escalation paths
- Triggers: repeated failure, low confidence, novelty, policy, user demand.
- Package: tried/outcomes, state, assessment, artifact refs.
- Escalations → golden-set cases; rate = health metric.
Kill switch & rollback
- Kill: seconds-to-zero, infra-independent, manual, drilled.
- Rollback: reversible-by-design or gated; runbook pre-written; post-incident audit from existing trails.
Code: The control plane as configuration
domains:
customer_refunds:
autonomy: act # earned: 99% success over 500 runs
bounds: { max_amount_usd: 200, reversible_only: true }
gates: [ { trigger: "amount > 200", action: require_approval },
{ trigger: "recipient_count > 10", action: require_approval } ]
escalation: { on: [failures>=3, confidence<0.6], package: full }
infrastructure_changes:
autonomy: recommend # not yet earned
gates: [ { trigger: "always", action: require_approval } ]
global:
kill_switch: { scope: [per_agent, all], drill: quarterly }
rollback: { backups: automatic, runbook: v3, signoff: oncall_lead }
audit: { append_only: true, includes: [gates, levels, escalations, actions] }