This paper proposes separating an agent’s Autonomous Capability Level (ACL), describing what it can technically do, from its Allowed Autonomy Level (AAL), describing what it is authorized to do in practice. The framework spans reactive execution, decision support, supervised action, goal-directed autonomy, and delegated operational authority. It also introduces a risk-aware process for assigning permissions based on oversight, reversibility, accountability, and organizational readiness. An enterprise data engineering agent is used to illustrate how a system with high capability can be deliberately constrained to a lower allowed autonomy level.
No heat snapshots are available in the last 24 hours.