AI Agent Acceptable Autonomy Matrix
An AI agent acceptable autonomy matrix classifies agent actions by risk, reversibility, data sensitivity, and tool scope, then assigns each action a defined autonomy tier: human-in-the-loop, human-on-the-loop, or fully autonomous. That tier is enforced through runtime policy and logged for audit, rather than left as a static governance document.
Mapping the matrix to runtime enforcement
Moving from classification to enforcement follows a consistent sequence, regardless of the tooling an agent calls.
Classify
Score each agent action by risk, reversibility, and data sensitivity.
Assign
Map each action to a defined autonomy tier.
Enforce
Apply the tier at runtime through policy, not prompt instructions.
Audit
Log every authorization decision for review and incident investigation.
Governance and audit requirements embedded in the matrix
A matrix is only as reliable as the governance discipline wrapped around it. The following requirements keep tier assignments accountable and current.
- Document who owns and approves each autonomy tier assignment, consistent with NIST AI RMF's Govern function.
- Log every tool call, its inputs and outputs, and the authorization decision made against it.
- Retain logs in a form usable for compliance review and incident investigation.
- Record least-privilege scope for each agent identity alongside its assigned autonomy tiers.
- Re-certify tier assignments on a defined schedule as tools or data access change.
- Keep design-time matrix documentation synchronized with runtime policy configuration to prevent drift.
What an acceptable autonomy matrix is
Classification dimensions that define risk
Practical decisions when building the matrix
- Score, do not describe: use numeric or ordinal scores for reversibility, data sensitivity, and impact rather than narrative risk descriptions, to keep tier assignment repeatable across teams.
- Treat the matrix as configuration, not documentation: if tier assignments only exist in a governance document and are not reflected in enforcement configuration, they cannot be relied upon during an incident.
- Expect tier changes over time: an action's assigned tier should change if its data access, reversibility, or downstream impact changes, which requires a review cycle rather than a one-time classification.
Move the matrix from document to enforcement
A matrix only reduces risk if assigned tiers are enforced at the point where an agent calls a tool, not just recorded in a policy document.
Explore Runtime Governance