Section 15 of 25 2 min read

Human Oversight, Governance, and Assurance

Approval design that resists fatigue, independent assurance, and governance of reduced-guardrail work.

Objective

Ensure autonomy expands through decisions with owners, and that control claims are independently verified.

Minimum bar (L2). Autonomy tiering applied to every agent. A review body with authority to block deployment. Written policy covering agent development, deployment, and decommissioning. A named accountable owner for every T2+ agent.

15.1 Controls #

IDControlMinimum bar (L2)Enforced state (L3)
GOV-1Fatigue-resistant approval designEvery human-in-the-loop approval point is documented with what the approver sees, what they are accountable for, and the expected request volume. Approval rate and median review time are captured even if not yet analyzed, so that rubber-stamping is detectable rather than invisible.Approval design that resists fatigue: batching, risk-weighted escalation, and periodic measurement of approval-rate-versus-review-time to detect rubber-stamping. An approval control with a 99 percent approval rate and a four-second median review time is not a control.
GOV-2Independent assuranceMaturity claims are self-assessed against the evidence requirements stated in each domain, with artifacts produced rather than asserted, and the assessment is reviewed by a function independent of the team that built the agents.Independent assurance — internal audit or an external party—verifying maturity claims against producible evidence rather than self-assessment.
GOV-3Governance of reduced-guardrail workEvery environment running models with safety classifiers reduced or disabled is inventoried, with a named owner and a stated purpose. Isolation for those environments is verified rather than assumed, and at minimum equals production.Explicit governance of reduced-guardrail work: named approver, isolation tier stronger than production, time box, monitoring, and a defined termination condition.
GOV-4Risk acceptance for autonomy expansionAutonomy tier changes are recorded decisions with a named signatory at the authority level Section 4 requires, and carry a review date. Promotion through demonstrated good behavior, without a decision, is prohibited.A risk acceptance process for autonomy expansion, with documented signatories, and periodic re-examination rather than one-time approval.
GOV-5Executive and board reportingAgent estate and governance metrics are reported to an executive owner on a defined cadence, with non-human identity reported separately from human identity. Coverage gaps are stated explicitly rather than omitted from the pack.Executive and board reporting using the metrics in Section 20, with non-human and human identity governance reported separately.

15.2 Evidence to Request #

  • Review board minutes showing at least one blocked or tier-reduced deployment.
  • Approval-rate and review-time telemetry.
  • The most recent independent assurance report.

15.3 Failure Modes #

  • A review board that has never said no, which indicates a rubber stamp rather than a control.
  • Policy written by security and never operationalized by engineering, so the control exists in a document and nowhere in the deployment pipeline.
  • Reduced-guardrail evaluation work conducted informally in research or red-team functions, unlogged and unapproved—the single most under-governed activity in most large engineering organizations, and the proximate condition of the most significant agent security incident to date.
PDF