Observe → approve → automate — on your terms
A trust ladder per (account, action type): start in observe, move to approve-each, then auto-with-rollback — graduated by real outcome evidence and demoted on the first bad signal.
Full autonomy is too much, too soon; manual approval forever is too slow. Teams need a dial they can turn per action type and per account, backed by evidence — not a binary "automation on/off".
Built to do the work, not just show it
Three levels, per action type
observe (watch only) → approve_each (human gate) → auto_with_rollback (unattended), set independently for each account + action type.
Honest outcome classification
Only verified successes count toward graduation; ambiguous outcomes are neutral, and any revert blocks promotion.
Demotion-first safety
A rolled-back post-check, a T+7 savings reversal, or a consumed override instantly drops the lane back to approve-each.
Soak-based graduation
A level only becomes eligible after a soak window of clean, verified evidence — promotion is one click, never automatic.
From signal to result
Observe
Watch the action type run through approvals and build a track record.
Graduate
When soak evidence is sufficient, promote one level up — re-checked at click time.
Demote
On any bad signal the lane auto-demotes, so trust is never assumed.
- Per (tenant, cloud account, action type) — cross-account safety holds for free.
- Autonomy decides only whether a human is asked; it never relaxes a guardrail.
- An unattended trigger runs only actions graduated to auto-with-rollback, off-process on a queue.
Questions
Does turning on autonomy remove approvals everywhere?
No — it’s per account and action type. Everything else still asks a human.
What makes a lane graduate?
Only verified successes over a soak window, with no demotion signals — and you still click to apply the promotion.