Brain Governance and Graduated Autonomy

The Tenant Brain is what every agent on your workspace reads before it answers. Governance is how you decide what an agent is allowed to write there without a person looking first — and how you take it back if it gets one wrong.

The default is conservative: every agent proposal waits for a human. Autonomy is something a proposer earns, per section, on its own track record — and you can withdraw it at any time.

What you'll need

Open Agents → Workflows → Tenant Brain, then the Governance tab. The settings below live in the Graduated autonomy card.

The five levels

Set the workspace default under Default level. Any section can override it, so you can run the whole brain at L0 and open up one well-understood corner, or run it open and lock down pricing/.

Level What an eligible agent may do
Human-only Agents cannot propose in the section at all.
L0 Every agent proposal waits for human review. This is the default.
L1 Eligible proposers' proposals auto-publish.
L2 Auto-publish, plus a post-hoc review window with one-click revert.
L3 Everything L2 grants, plus blessing Attested Computation concepts.

L3 is deliberately separate. A sanctioned computation is a number every agent will then compute the same way — so a wrong one is wrong authoritatively, across every conversation at once, rather than being one bad answer. Attested Computations therefore bless at L3 only, whatever trust a proposer has earned elsewhere. The human-authored deterministic attester stays the per-run backstop even then.

How a proposer becomes eligible

Eligibility is per proposer, per section — never global. An agent that has earned trust in playbooks/ has earned nothing in pricing/.

Two conditions, both set on the same card:

A decision is an approve, a reject, or an automatic action — every one writes a ledger row. Ten decisions at 90% is a deliberately slow bar to clear: it means you have actually seen that proposer's work before it stops asking.

Bulk acquisition never graduates. Knowledge pulled in by a crawl, an upload scan or the distiller always reviews at L0, whatever the settings say and whatever trust exists. Only proposals made in a conversation or through MCP can earn autonomy.

The post-hoc review window — your undo

At L2 and L3, an auto-published change opens a review row rather than simply landing. Set how long it stays open with L2 review window (hours); the default is 72.

While the window is open, the concept is already live and the row offers two buttons:

Two things about Revert worth knowing before you use it:

  1. It is immediate and exact. There is no queue and no approval step — the prior revision goes live as you click.
  2. It counts against the proposer. The ledger row for that publish flips from accepted to reverted. It does not add a second row, deliberately: one proposal must count as one decision, or a proposer whose work is always reverted would floor at 50% acceptance instead of falling toward zero.

A window that closes with no decision confirms the change. Rows past their window close as confirmed. That is the intended behaviour — but it means silence is consent, so treat an open review as work rather than a notification.

Read the sources before you decide

A concept in the review window arrived without you. The body and its citations are what you have to judge it on, so open it and check that its sources are real and say what the concept claims. A concept whose citations you cannot follow is the one to look at hardest.

Confidence-banded autonomy (optional)

A separate, opt-in path that publishes on the model's own confidence rather than the proposer's track record. It is off by default. When you enable it:

Audited band publishes appear in the same queue, tagged sampled audit, or band-edge audit where confidence only just cleared the threshold.

The other limits on this card

Setting Default What it does
Proposal TTL (days, 0 = off) 45 Pending proposals nobody decides expire from the queue. Expiry is logged and never counted against the proposer — a review backlog is not their fault.
Max tags per concept 6 (max 12) Tags beyond the cap are stashed losslessly, not discarded. Raise the cap and restore them from the same card.

Agents are also capped on how far they may grow the section taxonomy. Humans are not.

Troubleshooting

An agent proposal is still waiting even though the section is L1. Check the proposer's own record, not the section: eligibility needs both the acceptance threshold and the minimum decision count. A proposer with eight perfect decisions is not yet eligible at a minimum of ten.

A proposal carrying a lint error never auto-publishes. Lint errors gate graduated autonomy regardless of level or trust. Warnings do not.

Acquisition output always waits. That is by design — see the note above. Widening autonomy will not change it.

You missed a review window. The change is confirmed and live. You can still roll the concept back from its own history; it simply is not the one-click path any more, and the proposer keeps the acceptance credit.

Related

Sign in to KarmaFlow