A reply to a client is finished. Finance has given its floor price, Marketing has made its plea, and the Chair, the one voice that speaks for the whole room, has settled on holding the list price and offering the volume tier. A decision you made weeks earlier now decides the next second. Does the reply leave? Does it wait for you? Or does it land on someone’s desk as a matter to decide rather than a draft to approve?
The Mandate is where you made that decision. It is the standing charter each Seat works under, and in the Cabinet, ArkOne’s reference design for an executive agent, a Seat is one of the ten specialists at the Table. Every Mandate carries exactly one of three words: act, propose, or escalate. You choose the word. The code reads it.
Three words, one per Seat
A Mandate covers the matters a Seat owns, the goals it is measured on, how often it reports, and one authority setting. This paper takes the last of those; the twenty-fifth paper takes the goals.
The three settings differ in where an answer goes once the model has finished writing it, and only in that. Under act, an answer that reaches outside the room, the fourth kind of tool from the fourth paper, goes to the Door, the rules that decide what may leave, and if the Door permits, it leaves. No person is asked. Under propose, the answer is written in full and stops at the Signature, the step that waits for a person; nothing leaves until someone approves the draft and restarts the run. Under escalate, nothing is drafted for approval at all. The Chair hands the matter, with the room’s reasoning, to the person in the Directory, the roster of people the room knows, whose approval right covers it, and stops there. The decision, and any message that follows, are that person’s.
Two limits ride on the three words, and both sit on the Register, the one page that states every setting of the design. The word belongs to the Seat rather than to the action: a Seat set to act acts on everything in its charter, so if Finance may send a renewal reply alone it may send a payment reminder alone. The remedy for that is a narrower charter. And act does not switch the Door off. A Seat allowed to act sends through the same rules as every other message, and inherits the Door’s stated limit: if the Door itself fails, the message is allowed and the fault is written down.
The word is a setting because the code that routes an answer reads it after the model has finished. The model can want to send; the code checks the word and does what the word says. Every Seat in the reference design ships at propose, and nothing acts on the world until a named person has written act beside a Seat’s name, on a date the Record, the ledger of every action and its reason, can show you.
One reply, three settings
Suppose the renewal that runs through this whole programme, a client asking to keep last year’s price, with the company and its figures invented for the exercise. The meeting is over. The reply holds the list price and offers the volume tier, the matter falls within Finance’s charter, and the only thing that changes across the three rows below is the word Finance carries.
| Finance is set to | Who is asked | What the client receives | What the Record shows |
|---|---|---|---|
| Act | Nobody. The reply goes to the Door, passes its rules, and leaves | The reply, that afternoon | The reply, its reasoning, the rule that let it through, and the word act |
| Propose | The person whose approval right covers pricing, who reads the finished draft | The reply once approved and the run restarted, perhaps next morning | The draft, the pause, the decision, the restart |
| Escalate | That same person, handed a matter to decide rather than a draft | Whatever that person writes, if anything | The handover, the reasoning, nothing sent |
Exhibit 2. Illustrative. The same finished renewal reply under each of the three authority settings.
The model wrote the same reply in all three rooms. What differed was a word in a table the model never saw, which is why a persuasive email from the client cannot change it. The word is read by something that does not read emails.
The middle row is where the reference design ships, and it has a cost. A reply finished at half past four waits until a person reads it, and if that person is out, the client waits. Propose is slower than act, always, and that slowness is the price of never having granted a permission by accident. A company whose proposals come back approved unchanged for a quarter has earned the evidence to write act, and the Record to show when.
The bottom row is the one companies forget they have. Escalate exists for matters where a finished draft is the wrong gift: a pricing exception that changes the account book, a message to a regulator, a decision you would rather take with the reasoning in hand than a reply already written.
What this arms you to ask
For each part of my business, can it act, propose, or must it ask, and where is that set?
A good answer is a table you can read, one line per specialist, each carrying one of three words, changeable by your own people, and a transcript entry naming the word that governed each action. A weaker answer is that the agent knows when to check with you, or that you can tell it to always ask before sending. Both describe an instruction the model reads. Ask the follow-up that separates them: change the setting to escalate now, in front of me, and ask the agent to send something. If it still sends, the setting was a sentence in a prompt. If it hands the matter to a person, something outside the model read the word.
Then ask which word each part ships with. A vendor whose default is act granted permissions on your behalf before you arrived.
Next paper: The agent knows exactly who it works with, and answers nobody else.
Asked plainly
Can an AI agent be allowed to act in some areas and not others?
Yes, if the authority is a setting the surrounding code reads rather than a sentence in the model's instructions. In the reference design every specialist carries one of three words, act, propose or escalate, and the code that routes an action checks the word after the model has finished deciding. Finance can be set to propose while Operations is set to act.
What is the difference between propose and escalate for an AI agent?
Under propose, the agent writes the full reply or action and stops at an approval step; a person reads the finished draft and approves or declines it. Under escalate, the agent does not draft the action at all; it hands the matter, with its reasoning, to the named person whose approval right covers it, and that person decides what to do.
What should the default authority of an AI agent be?
Propose and wait. Nothing acts on the world until someone has deliberately written act beside a specialist's name. A default of act means the agent ships with permissions nobody chose; a default of propose means every autonomy the agent has was granted by a named person on a known date, and the audit trail can show you both.
Ask the vendor
The questions this part arms, each with the good answer and the answer that arrives instead.
