"Should we let the AI do it?" is the wrong question. The right one is "which things, under what limits, with what review?" That reframing is what autonomy levels provide.
- ›The full ladder from manual to self-optimizing
- ›The three mechanisms that make delegation safe
- ›How to choose a level per area
- ›When to move up, and the signals to move back down
Why a ladder
Binary thinking about AI autonomy produces two bad outcomes: teams that restrict AI to drafting and capture none of the value, and teams that turn it loose and spend weeks cleaning up.
A ladder replaces the binary with a decision you can make separately for each area of the business, and revise as evidence accumulates.
The ladder
| Level | Name | What the AI may do |
|---|---|---|
| 0 | Manual | Nothing. AI off for this scope |
| 1 | Assistive | Answer questions, summarize, when asked |
| 2 | Supervised | Draft and propose; every action needs approval |
| 3 | Conditional | Execute low-risk actions; escalate the rest |
| 4 | Delegated | Execute within an explicit list of allowed actions |
| 5 | Managed | Run scheduled work within limits, report by digest |
| 6 | Proactive | Initiate work from detected conditions, within limits |
| 7 | Autonomous | Operate the area end to end, escalate flagged risks |
| 8 | Self-optimizing | Additionally tune its own rules within bounds |
Most companies should run different areas at different levels indefinitely. Level 5 in internal task hygiene and level 1 in anything touching payroll is a coherent, mature configuration, not an unfinished rollout.
The three mechanisms
Levels above 2 are only safe with all three of these. A platform missing any of them cannot honestly offer them.
Explicit authority. A contract per scope defining allowed and denied actions, risk ceilings, monetary caps, quiet hours, and rate limits. Written as verbs, not intentions.
Complete audit. Every action recorded with what changed, at whose authority, and why, in a form that cannot be quietly edited. If you cannot reconstruct last Tuesday, you cannot delegate.
Reversibility. Most actions undoable, with windows scaled to risk, and whole runs undoable together. This converts delegation from a leap into a bounded experiment.
Important: Externally visible actions - a sent email, a posted message - cannot be unsent. Keep outward-facing verbs at lower autonomy than internal data changes for far longer than feels necessary.
Choosing a level
Ask three questions per area:
Moving up and down
Move up when the same proposals get approved unchanged for several weeks. That pattern means the review is adding no judgment and is a queue rather than a control.
Move down when you see approvals accumulating unread, corrections repeating, or any action you would have to explain to a customer. Moving down is not failure; a system that only ratchets up is a system without feedback.
FAQ
What level should we start at?
Level 2 globally. It costs some clicks and teaches you exactly what the AI would have done, which is the fastest way to calibrate everything else.
Can different agents have different levels in the same area?
Yes, and they should. A proven agent doing one narrow job can sit above the module default while an experimental one sits below it.
Is level 8 realistic?
For narrow, well-instrumented, fully reversible domains, yes. For anything customer-facing or financial, treat it as theoretical. The value of the top of the ladder is mostly that it makes the middle look reasonable.
Brainis implements the full ladder with authority contracts, a tamper-evident audit chain, and undo at both action and run level. See how autonomy works.
Sharing insights on business operations, AI, and modern team management.
Run your company on Brainis
All 11 Operating Systems on every plan, from $29 a month. No per-seat pricing — you pay for AI capacity, not headcount.
See pricing