A wall requires no signature It only needs a fear A gate requires a hand, a name And a date to reappear
Four days of diagnosis is three days more than this desk is comfortable with, so today the arc has to say what it wants, in a form somebody could take to a governance committee on Monday and lose an argument with.
The claim is one sentence. A control system that can only prohibit is not governing capability. It is avoiding responsibility for deciding where capability may safely operate.
That is not a call to open things. It is a call to make opening and closing the same kind of act, performed by the same named person, with the same evidentiary burden and the same route of challenge. At present one direction requires a decision and the other requires nothing, and any system with that asymmetry in it will drift in one direction regardless of what anybody intended.
Why the asymmetry exists
Give the current arrangement its proper reason before dismantling it, because it has one.
A restriction that turns out to be excessive produces a diffuse cost carried by people with no standing to complain about it. Slower work. A finding nobody made. Four hours a week absorbed by somebody at a desk. None of that arrives as an incident, none of it has a date, and no committee will ever review it.
A permission that turns out to be excessive produces a specific cost with a timestamp, a blast radius, and a named individual who approved it. It arrives as an incident report. It gets reviewed by people who know how it ended.
So the incentive is not obscure and nobody involved is a coward. In an accountability structure that punishes a defended decision more reliably than it punishes an undefended default, prohibition is the rational play. The competence budget gets spent, silently, by people who were behaving sensibly.
Fixing the drift therefore requires fixing the asymmetry rather than exhorting anybody to be braver. Make the closed envelope require an owner too. Give the restriction a review date. Put the removed capability in the ledger beside the reduced risk. The moment a default has to be defended on the same terms as a decision, the default stops being free, and a surprising amount of the problem resolves without anybody having to be persuaded of anything.
What an authorised yes contains
A governed expansion is a document, and it is shorter than the acceptable use policy it sits inside. But before the fields, the human cost. Somebody has to stand in front of a committee and defend a judgement about acceptable reach, with their name on it, at a grade high enough that defending it does not end their week. That person is the scarce resource, and the eight fields exist to make their job possible rather than to replace it.
Eight fields, and the discipline is that none of them may be left blank.
A governed expansion is a document, and it is shorter than the acceptable use policy it sits inside. Eight fields, and the discipline is that none of them may be left blank.
- The purpose for which context may be supplied, stated narrowly enough that somebody could tell when it had been exceeded.
- The memory that may persist, how long it persists, and the condition on which it is deleted.
- The tools available inside a threshold, with the actions that remain prohibited listed explicitly rather than implied by omission.
- The role of the system's inference in the final decision, which is where most organisations discover they have never actually decided this.
- The evidence and receipts required before work advances, in a form somebody outside the workflow could read.
- The owner who can defend the envelope, by name, at a grade high enough that defending it does not end their week.
- The parties with standing to contest it, which for this desk's readers means workers, affected communities, reviewers, and the people the decision lands on rather than only the ones inside the process.
- The trigger that narrows or suspends the permission, specified in advance, so that reversal is a procedure rather than a crisis.
Call the artefact an Operating Envelope Record if you need a name for the template, and then resist the immediate institutional urge to turn it into a universal checklist applied at uniform depth to everything. The fields have to be fitted to the purpose and the harm in play. A record filled in identically for two hundred workflows is a record that stopped being read after the fourth one.
Authority is not access
The distinction the week has been circling, stated properly.
Access is technical. It is whether a credential exists and what it opens. Authority is institutional. It is whether somebody with standing has decided that this use, in this relationship, is warranted, and remains answerable for having decided it.
Organisations conflate these constantly and always in the same direction. A tool is available, therefore its use is permitted. A connector exists, therefore the integration is sanctioned. The permission surface gets set by whatever the vendor shipped and whatever Security did not have time to close, which is a way of outsourcing an institutional judgement to a procurement cycle and a default configuration.
The Kiro outage is the cleanest available illustration and the reason this desk keeps returning to it. Amazon's account attributes the reach to a misconfigured role. The reporting attributes the operational choice to the agent. Both descriptions can hold, and either way the safety question sat at the join between what the system could do and what anybody had authorised it to do. The approved route had standing. That was why it could delete.
Access without authority produces that. Authority without access produces four days of this arc.
Somebody has already built one
The constructive turn is easier to make now than it was six months ago, because a regulator has published something that does this rather than merely recommending that somebody should.
Singapore's IMDA launched a Model AI Governance Framework for Agentic AI at Davos on 22 January, aimed specifically at systems that act rather than systems that answer. Read it for structure rather than for compliance, since it is voluntary guidance and this desk is not in the business of telling anybody which framework to adopt.
Four things in it are worth stealing.
It bounds the risk upfront by selecting the use case and then placing explicit limits on an agent's autonomy and its access to tools and data. That is the envelope as a design decision taken before deployment, by somebody, rather than as a configuration that fell out of whatever the vendor shipped.
It makes human accountability operational by requiring defined checkpoints at which approval is needed. A specified checkpoint is a different object from a general duty to oversee, and the difference is precisely what yesterday's episode spent its length on. One of them tells a person where they are expected to stop the work. The other tells them they are responsible for it.
It names automation bias in the launch announcement, describing it as the tendency to over-trust a system that has performed reliably in the past. Two decades of research finally arriving in a regulator's press release is a thing this desk notes with more relief than satisfaction.
And it is published as a living document, inviting feedback and case studies to refine it. Which is the reversibility principle applied to the framework itself, and a pointed contrast with every internal AI policy currently sitting untouched on an intranet since the quarter it was written.
The framework is not a solution and does not claim to be one. What it demonstrates is the existence proof the week needed: an instrument that can say yes at a specified level, with conditions attached and a checkpoint in the middle, is a thing that can be built. The reason most organisations do not have one is not that nobody knows how.
Expansion has to be earned, and the ratchet has to be broken
Two failure modes sit either side of this argument and both are common enough to name.
The first is expansion by optimism. Somebody was impressed by a demonstration, the envelope widens, and the widening is justified by enthusiasm and a slide. This is how organisations end up with an agent holding production credentials because a pilot went well in a context that shared nothing with production.
The evidence that should support a widening is duller. Did the loop perform at the current level, measured on the decisions rather than on the drafting. Can the practitioners at this stage actually interrogate the output, demonstrated rather than asserted. Are the receipts good enough that somebody could reconstruct a decision six months later without asking anybody. Is the action recoverable, and has anybody tested the recovery rather than documenting it.
The second failure mode is the one-way ratchet, and it is the more dangerous because it looks like progress. An envelope that only ever widens is not being governed either. New evidence has to be able to close it, the trigger for closing has to be written down in advance while everybody is calm, and somebody has to have the authority to pull it without a three-week escalation.
Refusal stays live. That is the difference between governed expansion and a procurement relationship that got away from everybody.
The part the Exit arc requires
And here is the provision that would not have been in this episode a fortnight ago, before the arc that just closed put a condition under the whole programme.
Everything above is voice. It is an apparatus for contesting and revising an institution's decisions from inside, and it works exactly as long as the institution keeps listening. The Exit arc's finding was that a settlement holding only voice is a floor plan for a building with no way out.
Indoors, the second column is smaller and unglamorous and mostly about portability.
Portable prompts and evaluations. The accumulated tuning, the test cases, the record of what this workflow needs a system to get right, held in a form that survives a change of vendor. Without them, an organisation's only options are captivity inside the approved service or the invisible tab, which is the choice Friday's episode watched people make.
A procurement question about unavailability. Not what the system does. What happens to the work if this supplier is unavailable for eighteen days, which acquired a date in June and is no longer a hypothetical anybody gets to wave away.
Refusal of irreversible integration. A workflow that cannot be moved is a workflow whose terms will be renegotiated by somebody else at a time of their choosing.
None of this is about disloyalty to a vendor. It is the recognition that an operating envelope granted by a party who can revoke it is a courtesy with a governance vocabulary on top, and the whole of last fortnight was about what happens when the grantor changes their mind on a Thursday afternoon at twenty past five.
The practitioner is a control
The last piece, and the one most likely to be cut from the budget.
Wider capability is frequently safe only because a person can interrogate it, contest it, and stop it. That person is not an accessory to the deployment. She is a load-bearing element of it, and the envelope she can safely operate is wider than the envelope somebody untrained can safely operate, which means the same technical configuration has two different risk profiles depending on who is at the desk.
Formation is therefore a governance control and belongs in the control column of the budget, sitting next to the audit spend rather than in the adoption line where it currently lives and where it is cut first every time margins tighten.
This also supplies the honest answer to a fair objection. If capability can widen, who stops it going too far? Somebody who understands it well enough to know when it has, holds enough standing to say so, and works inside a structure where saying so is a procedure rather than an act of career risk. That is expensive. It is considerably less expensive than the alternative, which the whole week has been describing.
Tomorrow the arc closes, and it has one question left that everything has been building toward. If an organisation never authorised meaningful reach, never owned the composition of its restrictions, never measured what left the counted world, and never resourced the person holding the loop together, then its AI trial produced a real result.
What the result is a result about is the interesting part.
Anyone can build a wall. A gate needs somebody willing to have their name on the hinge.
Companions
- The controls this returns to enterprise scale: Counting Gardens and The Loop That Governs the Loop.
- The condition placed under the whole programme: The Remedy Went the Forbidden Way and the Exit arc.
- A regulator's version of a ladder rather than a switch: IMDA's Model AI Governance Framework for Agentic AI, with commentary from AI Asia Pacific Institute and Baker McKenzie.
- Where access and authority came apart: The Door at the Desk on the Kiro incident.
- The person who makes a wider envelope safe: The Human in the Display Case and The Ones Who Carry It.
- The contractual layer this has always needed: The Calvin Convention.
These notes come out of Sociable Systems, a practice that reads AI-shaped documents the way a hostile reviewer will, before a lender or a court finds the gap. The argument has an operational form: the Interim Protocol sets out four rules for AI use in environmental and social deliverables, covering disclosure at touch-point grain, evidence custody, the phrases no automated screening may settle, and a hostile read before anything ships. Free, and written to be cited or retired once institutional guidance arrives.
