Hetu.

Platform / Autonomy & governance

Autonomy is granted per decision type, and it can be taken back.

The envelope starts closed. It widens where measured outcomes prove the system right, and narrows on its own when they stop — including when the world changes underneath a decision type that used to work.

Envelope mechanics

Four moving parts.

Per decision type

01 · Scope

Autonomy is never granted to “the agent.” It is granted to a named decision type at a named confidence label, within a magnitude band.

Outcome-gated

02 · Evidence

A type moves inside the envelope after a minimum count of decisions whose measured outcome at T+7/14/30 matched the predicted impact within tolerance.

Magnitude-capped

03 · Ceiling

Inside the envelope is not unlimited. Each type carries a value or exposure ceiling above which a named approver is required regardless of accuracy.

Automatic narrowing

04 · Reversal

Accuracy falling below the retention threshold, or a regime-change signal, moves a type back out. Narrowing does not require a human to notice.

Ruin thresholds

Some decisions never auto-execute, whatever the score says.

Irreversible

The action cannot be undone within the measurement window — funds disbursed, a customer terminated, a filing submitted.

Named approver, always.

Fat-tailed

The loss distribution has no bounded worst case at the proposed magnitude.

Named approver, always.

Correlated

The action repeats across a cohort, so a single wrong premise compounds instead of averaging out.

Batch cap plus approver.

Bounded

Reversible within the window, with a known worst case inside the ceiling.

Eligible for autonomy.

These are circuit breakers, not confidence adjustments. A CONFIRMED label on an irreversible fat-tailed action still requires a human, because the question the label answers is not the question the breaker asks.

Regime change

Calibration assumes the world stays still. It doesn't.

A decision type earns autonomy against a distribution. When that distribution moves — a rate cycle, a channel mix shift, a platform algorithm change, a new product — historical accuracy stops predicting future accuracy, and the envelope has to close before the outcomes prove it.

The detector watches feature drift and residual structure on the fitted models, not just outcome accuracy, because accuracy is the lagging indicator. A drift signal moves affected types back to approver-required and flags the graph for re-seeding.

The two rules that survive calibration

Everything else in the envelope is learned. These are not.

Never auto-execute an irreversible, fat-tailed action.

No accuracy record buys past this. The reason is asymmetry, not uncertainty: the upside of being right is bounded and the downside of being wrong is not.

Never narrate above the computed label.

A medium-confidence result cannot be presented as a root cause, no matter how well that decision type has performed. The label is the contract with the person acting on the output.

Next

Then look at what your auditor will be handed.

Every decision, approval, deferral, execution and outcome, in one immutable record.