In short
An authority envelope is the set of actions an AI may take on a program without asking a person. It is defined per program and per kind of action, starts narrow, and widens only as the record shows it is safe. Anything outside it goes to a named human approver.
Why not simply trust it, or not?
Because trust is not one thing. A vice president might be comfortable letting software chase an overdue update today and not comfortable letting it reassign engineers for a long time. Both positions are reasonable, and both can be true at once.
What are the stages?
Authority is earned in order:
- Observe: it shows the program as it is. People do everything else.
- Diagnose: it names the cause of each drift, with the evidence.
- Recommend: it proposes a repair with the impact quantified. A person approves or rejects each one.
- Act: it carries out the kinds of action that have been approved, and sends a receipt.
What goes inside the envelope first?
Low-risk, reversible actions: chasing an owner, requesting evidence, re-sequencing a sprint, drafting a note for a person to send. High-consequence decisions stay outside it. On a chip program, no AI Employee approves a tape-out gate.
How do you know it stayed inside?
Every action is checked against the envelope at the moment it runs, and the check is written into the receipt. An attempt outside the scope is blocked and logged.