A cross-cutting lens

When AI acts, not just answers

Agentic AI doesn't just produce output, it takes action on your behalf. That moves the human out of the loop by default, and that's where oversight, accountability, and audit need a higher bar. A lens on the pillars you already have.

Most of this framework quietly assumes AI that answers: it drafts, summarizes, suggests, and a person decides what to do next. Agentic AI is different. It acts, it books the room, sends the email, updates the record, moves the money, and chains several steps together to reach a goal you set once. That shift, from a tool you operate to a system that operates on your behalf, is where existing assumptions about oversight, accountability, and audit quietly break. This page is a lens, not a new pillar: it stresses the pillars you already have and shows where agentic use needs a higher bar.

Answers vs. acts

The distinction that matters isn't how smart the model is, it's whether a human stands between the output and the consequence.

Assistive / generative AI

Produces an output, text, an analysis, a recommendation. A person reviews it and chooses whether to act. The human is the gate.

Agentic / autonomous AI

Takes the action itself, often several in sequence, using tools and system access to reach a goal. The human may only see the result. The gate has moved, or gone.

What quietly breaks

Agentic use doesn't need new values, it needs the existing ones enforced at a point where a human is no longer in the loop by default. These are the assumptions that quietly fail.

Human oversight

P7
The old assumptionA person reviews each output before anything happens.
Under an agentApprove what, exactly? Oversight has to move from 'review every output' to 'set the bounds, sample the actions, and be able to stop it.'

Accountability

P7
The old assumptionThe person who acted is answerable for the action.
Under an agentWhen the agent acted, who owns the outcome, the operator, the unit that deployed it, the vendor? Accountability must be assigned before deployment, not after harm.

Auditability

P8
The old assumptionA decision has a record and a rationale.
Under an agentAn agent's outcome is the end of a chain of steps and tool calls. Without logging the whole chain, you can't reconstruct why it did what it did.

Data & system access

P4
The old assumptionAccess is scoped to what a person needs to do their job.
Under an agentAn agent often needs broad reach across systems to be useful, which makes it a powerful identity that can act widely. Scope and credential it like one.

Failure blast radius

P8
The old assumptionA mistake is one wrong output a person can catch.
Under an agentAn autonomous mistake can repeat across hundreds of records or messages before anyone notices. Reversibility and a kill-switch stop being nice-to-haves.

The autonomy ladder

Autonomy isn't on or off, it's a ladder. Naming the rung an AI use sits on is the single most useful move in governing it, because the required controls rise with each step. Place a use on the lowest rung that still delivers the value.

1

Suggest

Proposes an option; a person does everything.
Who actsThe human acts. AI only informs.
Governance barStandard AI literacy and disclosure. Low bar.
2

Draft for approval

Prepares the action fully, but nothing happens until a person approves it.
Who actsThe human is the gate on every action.
Governance barClear review step; the approver is named and accountable.
3

Act with confirmation

Executes routine steps, but pauses for explicit sign-off on consequential ones.
Who actsThe human gates the risky actions, not all of them.
Governance barDefined thresholds for what needs confirmation; logging of what proceeded automatically.
4

Act within bounds

Operates autonomously inside pre-set limits, scope, spend, record types, and escalates anything outside them.
Who actsThe human sets the fence and monitors; the agent runs inside it.
Governance barScoped permissions, hard limits, full action logging, monitoring, and a kill-switch. High bar.
5

Fully autonomous

Pursues a goal end-to-end with no routine human checkpoint.
Who actsThe human sees results, and after-the-fact review.
Governance barRarely justified for consequential campus decisions. Requires the highest scrutiny, strong reversibility, and an explicit governance decision to allow it.

The ladder is a governance tool, not a maturity goal. Higher rungs are not better, they're riskier. The right rung is the lowest one that does the job.

Guardrails, mapped to your pillars

The controls that make higher rungs safe aren't new inventions, they're your existing pillars, applied at the point of action. Each maps to where it already lives in the framework.

Scoped permissions

Give the agent the narrowest system access and credentials that let it do its job, and treat it as a named identity, not a shared key.

Pillar 4 · Governance, risk & data

Named accountability

A specific person owns the agent's actions and answers for them, decided before it's deployed, not discovered after an incident.

Pillar 7 · Roles & responsibilities

Right-sizing it: campus scenarios

What right-sizing looks like in practice. The point of each is the rung and the fence, not the technology.

A student-advising agent

An agent that can answer student questions and take actions, registering for a workshop, flagging an advisor, adjusting a plan.

Right-sized

Rung 3, act with confirmation. It can book a workshop seat on its own (low stakes, reversible) but must route anything touching a student's academic record or standing to a named human advisor. Every action logged; the student always told when they're talking to an agent.

Over the line

Letting it change enrollment or academic plans autonomously, high stakes, hard to reverse, and directly affecting a student's record.

An operations / procurement agent

An agent that handles routine back-office tasks, drafting POs, reconciling invoices, chasing approvals.

Right-sized

Rung 4, act within bounds. Autonomous under a hard spend cap and only for pre-approved vendors and categories; anything above the cap or off-list escalates to a named budget owner. Full audit trail sized to survive a records request.

Over the line

An open-ended spend authority with no per-action cap, one bad loop can commit real money across many transactions before anyone looks.

A communications agent

An agent that drafts and sends routine messages to students or staff.

Right-sized

Rung 2–3. Drafts freely; sends automatically only for a narrow, pre-approved class of routine notices; anything sensitive, unusual, or to a large audience waits for human sign-off.

Over the line

Autonomous send to large audiences, a single templating or targeting error reaches thousands before it can be caught.

Screen agentic use-cases at a higher bar in the Strategic CompassAgentic initiatives carry more operational and ethical risk, weight them accordingly when you score and sequence them. The Compass is where that judgment gets recorded.Open it
The question isn't whether AI is capable of acting. It's whether you've decided, deliberately, how far it may.