Governed autonomy

L0–L7: how much should your AI do?

Eight levels, from observe-only to operating a scope end to end. The useful question is not which level is best but which level each domain of your company has earned.

5 min readGoverned autonomy

A ladder with eight rungs is more useful than a switch with two positions, for the same reason a dimmer is more useful than a light switch: the interesting settings are in the middle, and they are different for different rooms.

Brainis runs eight autonomy levels, L0 through L7. What follows is the shape of the ladder, what changes at each step, and — more usefully — how to decide which rung a given domain of your company belongs on today.

What you’ll learn

  • What each level permits, in one line
  • The two steps where the character of the system changes
  • Why levels are per-domain, never global
  • The three signals that say a domain is ready to move up

The ladder

L0 — observe. The system reads state and does nothing else. No drafts, no suggestions. Useful for the first weeks in a sensitive domain, because it produces a record of what the system would have noticed without producing anything to argue about.

L1 — suggest. It flags and recommends. A person does everything.

L2 — draft. It produces the artefact — the email, the plan, the analysis — and a person reviews and sends. Most companies live here longer than they need to.

L3 — execute the reversible. It performs actions from an explicit allow-list, all of them reversible within a short window, inside stated value and rate limits. Anything outside the list becomes a question.

L4 — execute with notice. Wider action scope, including some irreversible actions, with notification before the action rather than after, and a window in which a human can stop it.

L5 — operate a workflow. It runs a defined process end to end, escalating on exception rather than on every step. The human relationship changes here from approving to supervising.

L6 — operate a domain. It owns outcomes across a domain, sets its own sequencing within the domain's constraints, and escalates on risk class rather than on step type.

L7 — operate across domains. Coordination across domains inside the contract, with escalation reserved for the never list and for anything crossing a declared risk ceiling.

Every level sits inside an authority contract. The level is a preset over the seven dimensions — action, domain, value, risk, reversibility, time, owner — described in autonomy is a contract, not a replacement for them.

The two steps that change the character

Six of the seven transitions are incremental. Two are not.

L2 to L3 is the trust threshold. Below it, every consequence passes through a person. Above it, software takes actions that touch the world. Everything about how you evaluate the system should change at this line: you stop reading outputs and start reading the record of actions.

L4 to L5 is the supervision threshold. Below it, a human is in the path of each action. Above it, a human is watching a process and intervening on exception. This is a genuine change in what your day looks like, and it is the step where teams most often move faster than their governance is ready for.

Important: Crossing a threshold is not a settings change. It is a change in what you are responsible for reviewing. Move up a rung and immediately ask what you have stopped looking at, then decide deliberately whether that is acceptable.

Levels are per-domain

The single most common mistake is treating the level as a company-wide setting.

Your company is not uniformly ready. Marketing copy drafting might be comfortable at L4 while anything touching payroll sits at L1 indefinitely and should. A domain's rung depends on how reversible its actions are, how quickly errors surface, how much evidence exists about performance in that specific domain, and how much it would cost to be wrong.

Per-domain levels also make the ladder legible. "We are at L4" says nothing. "Content is at L4, revenue operations at L3, finance at L1, and people at L1 with a never list" describes a company someone can reason about.

The three readiness signals

A domain is ready to move up when three things are true. Not two.

Volume. Enough actions at the current level that the record means something. A handful of clean runs is not evidence, it is a small sample.

A clean rejection record. Work that was caught by verification before it shipped, at a rate that is stable rather than rising. A domain with zero rejections is not a safe domain — it is usually an unexamined one.

A tested escalation path. Someone has actually been escalated to, and responded, within the time the process assumes. Untested escalation paths fail on the day they are first needed.

If a domain has volume and clean rejections but no tested escalation, test the escalation before moving up. That is a week of work and it is the week that matters.

What holds the ladder up

Levels only mean anything if the system can stop. Circuit breakers watch every action class against learned baselines and halt in graduated steps — throttle, pause, full stop — before anyone has to notice.

Graduated matters. A binary halt is either too eager, in which case people disable it, or too slow, in which case it fires after the damage. Throttling first catches the common case, which is a rate anomaly rather than a catastrophic one.

This is the same reason the honest headline for a system like this is that it stops itself, not that it does not make mistakes. An AI that cannot stop is not safer at L1 than at L7. It is just slower to reach the failure.

The agents themselves, and what each one is permitted to touch, are described on the agent fleet. The levels, grants, and halt behaviour are on autonomy.

Where to start

If you are choosing a first rung: pick L3, in one domain, with a six-week grant and a short allow-list of reversible verbs.

L3 is the lowest rung that produces evidence about action rather than about output quality, and evidence about action is what every later decision depends on. Starting at L1 feels prudent and generates almost nothing you can use.

Governed autonomyDeliver

Brainis Team

Notes on the company loop — company state, decisions, governed autonomy and verified work — from the people building Brainis and running on it.

Bring Brainis the company you want to build.

Start from an idea. Connect what exists. Either way, leave with the next move — and a system that delivers it.