Control Design

An agent's autonomy isn't a switch — it's a dial. Approval gates, autonomy levels, escalation paths, kill switches: the control design that makes autonomy shippable.

▶ Watch this reel

What you'll learn

  1. Approval gates
  2. Autonomy levels
  3. Escalation paths
  4. Kill switch, rollback & audit

Remember this

Approval gates

Autonomy levels

Escalation paths

Kill switch & rollback

Code: The control plane as configuration

domains:
  customer_refunds:
    autonomy: act                      # earned: 99% success over 500 runs
    bounds: { max_amount_usd: 200, reversible_only: true }
    gates: [ { trigger: "amount > 200", action: require_approval },
             { trigger: "recipient_count > 10", action: require_approval } ]
    escalation: { on: [failures>=3, confidence<0.6], package: full }

  infrastructure_changes:
    autonomy: recommend                # not yet earned
    gates: [ { trigger: "always", action: require_approval } ]

global:
  kill_switch: { scope: [per_agent, all], drill: quarterly }
  rollback: { backups: automatic, runbook: v3, signoff: oncall_lead }
  audit: { append_only: true, includes: [gates, levels, escalations, actions] }