From human approval to runtime authority
A human approving an AI-agent workflow does not prove the workflow will remain within the approved boundary.
Authority is the enforceable set of actions the running system can actually perform.
The practical objective is to make autonomy legible, constrained, observable and reversible.
Ten questions every CISO should ask
- What exactly is running?
- What is it authorised to do?
- Which resources may it reach?
- What risk policy applies?
- What consequential action was attempted?
- What independently observed the outcome?
- Can authority be stopped or revoked?
- What evidence supports the decision?
- What changed?
- What still requires a human?