# 7.2 The autonomy ladder (/managing-ai-workers/the-authority-envelope/autonomy-ladder)

---
type: Document
title: "7.2 The autonomy ladder"
description: "The four levels of authority a worker can have for each action, the line that matters most, and how a worker stops and asks a person at any level."
status: stable
order: 207.2
ksor:
  owner: team:panaversity
  audience: [ public ]
  approval:
    by: process:panaversity
    at: 2026-10-06T21:02:42Z
chapter: "07"
part: II
expert_status: required
concepts: [ "7.2" ]
last_verified: 2026-10-07
sources:
  - id: v1-governance
    title: "Governance, Risk & Responsible Use: A Crash Course (Panaversity, first edition, verified 2026-10-07)"
    resource: https://agentfactory.panaversity.org/docs/governance-risk-responsible-use-crash-course
generated:
  at: 2026-10-06T21:02:42Z
  by: esl-rewrite/1.2.0+ksor.1
trust_tier: unverified
build_id: sha256:c93b28093c2f70c60faae2645a693d881b657ff94d00f7dd9f8c06427ff61c87
dirty: true
ksor_version: 0.0.60
---

**In everyday life.** A house sitter looks after your home while you are away. They may check the mail (observe), suggest calling a plumber (recommend), write a note to the neighbor for you to approve (draft), or call the plumber and pay them (execute).

Every action an AI Worker might take sits on one of four rungs, or levels, like the steps of a ladder. Each rung includes the ones below it. The examples come from Brightline's AP Worker, the AI Worker that handles the bills the company owes.

| Rung | What the worker does | What changes | AP example |
| --- | --- | --- | --- |
| *Observe* | Reads and reports | Nothing | Reads the open invoice list and a vendor record |
| *Recommend* | Proposes a decision a person makes | Nothing yet | "Hold invoice 5161 under policy 5.3" |
| *Draft* | Prepares the thing itself, ready for a person to release | Nothing until a person releases it | A vendor reply saved as a draft, the run proposal |
| *Execute* | Takes the action | Something outside the conversation | Sends an email, writes to a record, pays |

Execute comes in two forms. The worker acts alone, or it acts after a person approves each action. Approval each time is still execute, because once you say yes, the worker sends. At draft, a person sends.

The line that matters most is between draft and execute. A draft waits for a person. An executed action has already happened. In this chapter's story, Maria asked the worker to answer vendors' questions, and its settings let it send the answers itself. "Answer vendors" became "send to vendors," and nobody decided that the worker should move from draft to execute.

Rungs are set per action, not per worker. There is no "level 3 worker." The AP Worker may observe bank details, draft vendor replies and execute nothing at all.

**Escalate is not a rung.** To escalate is to stop and hand a question to a person, and it is available at every rung. When the worker reaches a limit, meets an exception or has real doubt, it stops. It hands the question to a named person, with the evidence and what it did not do. If it can message no one, it puts the question at the top of its report. The governance course in this book's first edition puts it simply: escalate the question, not a verdict.[^v1-governance] A verdict is a final judgment. "I think this is fraud" is a verdict. "This email asks to change Scioto Pallet's contact email. Policy 5.4 says I may not act on it. Maria verifies, and Dave approves any change. I changed nothing" is a question. Maria is Brightline's office manager, and Dave is its controller.

![The title reads "The autonomy ladder." The line below it reads "Four rungs. Authority is assigned per action. Escalation is available at every rung." Four numbered rungs climb toward more authority. One, Observe: reads and reports, for example reads the invoice list and vendor records. Two, Recommend: proposes a decision for a person to make, for example recommends holding an invoice under policy. Three, Draft: prepares work for a person to release, for example a vendor reply or payment-run proposal. Four, Execute, in red: the worker takes the action, such as sending an email or changing a record, if authorized. It acts within standing authority or after approval each time. A gold band between Draft and Execute asks who releases the work. At draft it is a person, and at execute it is the worker. Dashed arrows from every rung lead to a gold box, Escalate, which is available at every rung and is not a fifth rung. At a limit, an exception or uncertainty, the worker stops and asks a named person. The box lists the question, the evidence, what was not done, and who decides. It ends: escalate the question, not a verdict. A footer reads: approval before each action is still Execute if the worker performs the action. Brightline's AP Worker may observe, recommend and draft. It has no execution authority today.](img/autonomy-ladder.png)

*Figure 7.2. The autonomy ladder. The gold band marks who releases the work.*

[^v1-governance]: Governance, Risk & Responsible Use: A Crash Course, Panaversity, first edition.
