# 7.1 The envelope, the brief and the permissions (/managing-ai-workers/the-authority-envelope/envelope-brief-permissions)

---
type: Document
title: "7.1 The envelope, the brief and the permissions"
description: "The three things that limit what a worker does: the standing decision its owner writes, the narrower limit of one task, and the product settings that make both real."
status: stable
order: 207.1
ksor:
  owner: team:panaversity
  audience: [ public ]
  approval:
    by: process:panaversity
    at: 2026-10-06T21:02:42Z
chapter: "07"
part: II
expert_status: required
concepts: [ "7.1" ]
last_verified: 2026-10-07
sources:
  - id: v1-thesis
    title: "The Agent Factory Thesis (Panaversity, first edition, verified 2026-10-07)"
    resource: https://agentfactory.panaversity.org/docs/thesis
generated:
  at: 2026-10-06T21:02:42Z
  by: esl-rewrite/1.2.0+ksor.1
trust_tier: unverified
build_id: sha256:c93b28093c2f70c60faae2645a693d881b657ff94d00f7dd9f8c06427ff61c87
dirty: true
ksor_version: 0.0.60
---

**In everyday life.** A teenager's curfew, the time they must be home, is 11 p.m. A parent can say "home by 10 tonight." Nobody can say "stay out until 1 a.m." without changing the curfew. And either way, the car keys decide what is possible.

Three different things limit what an AI Worker does. Keep them apart.

**The Authority Envelope** is the explicit, standing boundary of what a worker may observe, recommend, draft, execute or escalate, including **thresholds** and the actions that may never be automated. Thresholds are the numbers where a level or an approver changes. To escalate means to stop and ask a person. Explicit means it is stated clearly, in writing. Standing means it belongs to the worker, not to one task. It lives in the worker's Role Contract, the one-page definition of its job, in the part on authority. The worker's owner writes it. The worker does not, and neither does the person who writes today's brief, the written instructions for one task. At Brightline, the wholesale company in this book's story, the AP Worker handles the bills the company owes. Dave, the controller, owns its envelope.

**Autonomy in the brief** (Chapter 5) is the part of a brief that sets how far one task may go. It can only make the envelope narrower, never wider. "Draft replies, send nothing" is fine. "Pay anything under $5,000" cannot widen an envelope that says the worker never pays.

**Permissions** are the product settings that decide what the worker's tools *can* do: which connectors to other apps, such as email, are on, which tools need approval, which folders and logins it can reach. The envelope is the decision. Permissions enforce it, which means they make the tools follow it.

An envelope has four parts:

1. **Actions and levels.** Every action the worker might take, each with its level.
2. **Thresholds.** For example, "over $5,000," above which Dave must approve.
3. **Never automated.** Actions that no setting may ever let the worker do, such as releasing a payment. Chapter 6, on checking a worker's results, moved the question "what must never happen automatically?" here, because it limits the worker, not the review.
4. **Escalation triggers.** When the worker must stop and ask, and whom it must ask.

The first invariant of this book's first edition is "The human is the principal." An invariant is a rule that never changes, and the principal is the person the worker acts for. That invariant says the principal draws the authority envelope.[^v1-thesis] This chapter makes that envelope a written record.

![The title reads "The envelope decides. The brief narrows. Permissions enforce." The line below it reads "Define what the worker may do, then limit what its tools can do." On the left, a large gold box is the Authority Envelope: standing authority, written by the worker's owner and kept in the Role Contract. It has four labels, actions and levels, thresholds, never automated and escalation triggers. Its AP example says the worker never pays. Inside it, a white box, Autonomy in the brief, sets how far this task may go. It can narrow the envelope, never widen it. Its green example is allowed: draft replies to vendors, send nothing. Below the gold box, a red box marked outside the envelope reads: pay anything under $5,000, because a task brief cannot grant payment authority. On the right, a box headed Permissions, what the tools can do, lists enabled connectors, allowed actions and approvals, accessible folders, and connected accounts and logins. An arrow labeled enforce the limits points from it to the envelope. Its red note says to match the envelope and the task, no wider. Below that, it says a draft-only task has sending disabled. A footer reads: At Brightline, Dave Kowalski owns the envelope. The worker cannot expand its own authority.](img/envelope-brief-permissions.png)

*Figure 7.1. Three limits, one inside the other.*

[^v1-thesis]: The Agent Factory Thesis, Panaversity, first edition.
