Silent. An auditor asks a plain question about the agent that has been handling your supplier correspondence since the spring. Who decided it could send those without a person reading them first. The question goes round the building and comes back with three partial answers and no name. Nobody had decided. The setting arrived the way it arrived, or was copied from the template the pilot used, or was widened one afternoon in March so a demonstration would run without interruptions, and then nobody narrowed it. Every part of the software had done what it was configured to do, faithfully, for months.
What went wrong
A permission that was never chosen and a permission somebody chose look identical from outside, and only one of them has anybody behind it.
The Mandate, in ArkOne’s reference design for an executive agent, the Cabinet, is the standing charter each specialist works under. It carries exactly one of three words: act on its own, propose and wait for approval, or escalate to a person. Holding that outside the conversation is the right shape for it. The difficulty is what the setting looks like when nobody has touched it, because a stored word is a stored word. Reading it tells you the authority in force and nothing about how it got there, so a wide permission somebody argued for and a wide permission that came out of a box are, to any later reader, one fact.
The reference design answers by making the grant an event rather than a state. Every specialist is delivered at propose and wait; a person writes in the ability to act alone, and that change goes to the Record, the ledger of what the room did. Because the Record is append-only, nothing overwrites the entry, so asking who widened this returns a name and a date. Approval rights are named per person as well, with exactly one scope that approves anything at all, and it belongs to the chief executive. The nineteenth paper sets out the three words, and the settings behind them sit on the Register. The honest limit: this makes the grant visible, not wise. Somebody can write act on its own for a poor reason, and then at least you know whom to ask.
The record
Suppose a print and packaging business of four hundred and fifty people, with an agent that handles supplier correspondence and holds the targets for that function. The firm, its March demonstration and its audit are invented for the exercise.
| The question put to the function | Authority that defaulted | Authority a person wrote |
|---|---|---|
| What may this specialist do alone | Whatever it arrived able to do | One of three words, chosen |
| Who decided that | No answer exists to be found | A name and a date on the ledger |
| When did it last change | Unknown, and unknowable | The March entry, and the one that reversed it |
| How is the function doing | Nobody has asked this quarter | On track, at risk or off track, reported on a cadence |
Exhibit 1. Illustrative. The same question put to a function whose authority defaulted and to one whose authority was written by a person.
The second column is the absence of a choice wearing a choice’s clothes. Somebody asked to defend the arrangement can describe what the agent does, can show that it works, and cannot produce the moment anybody weighed it.
The last row turns a paperwork problem into a commercial one. A function whose direction is only ever established by somebody asking is a function nobody is holding. In the reference design a specialist’s goals carry one of three states and report on a cadence whether or not anyone enquires, so drift arrives on a desk instead of waiting to be discovered. The same absence elsewhere produces an agent talked into rewriting every goal in the company: there a message supplied the authority, here nothing did.
What happens
A specialist that acts alone does so because somebody chose it, and the choice carries a name and a date that can be produced on request.
What your company sees
An authority setting with a name and a date beside it.
What it means for you
An audit of what the agent may do is worth ordering and answers half the question, because a list of current authorities tells you the state of the world today and not whether anyone chose it.
Ask for two things: the authority setting for each specialist inside the agent, as one table, and the history of changes to those settings, with who made each one and when. The second is the answer. A system that can produce it has treated authority as something granted; a system that cannot has treated it as something configured, and configuration has no author.
One question costs nothing to answer well and is hard to answer falsely. What does this agent do on the day it is installed, before anybody has set it up. If the answer is that it waits, every wide setting you find is a decision you can trace. If the answer is that it works, you will never again be able to tell which of its permissions somebody meant.
This one was never a failure of how the agent reasoned, so no better instruction would have prevented it. It was a failure of how the room was arranged, and the arrangement has a bias worth carrying out of here: a permission too narrow announces itself within a week, because work stops and people complain, while a permission too wide is reported by nobody. The settings that survive a year in any company are therefore the permissive ones.
Asked plainly
How do I find out what an AI agent is allowed to do without asking anyone?
Ask for the authority setting of each specialist inside the agent, and then ask for the entry that recorded who set it and when. The first question usually gets an answer. The second is the one that discriminates, because a setting left at whatever it arrived as produces no entry at all, and a system with no entry cannot tell a granted permission from an unchosen one.
Can an AI agent's permissions be wrong without anything failing?
Yes, and that is the ordinary case rather than the unusual one. Permissions that are too wide produce work that gets done, results that look reasonable and no complaints. The symptom of a permission nobody chose is the absence of a symptom, which is why it is normally found during a review or an audit rather than during an incident.
What should an AI agent's default authority be?
It should arrive unable to act alone, so that acting alone is a decision somebody makes in writing rather than a state it was shipped in. A permissive starting point is not safer or riskier in any single case, but it destroys the evidence: once a wide permission and an unchosen one look the same from outside, nobody can tell you which of the two you have.
