When AI acts, not just answers
Agentic AI doesn't just produce output, it takes action on your behalf. That moves the human out of the loop by default, and that's where oversight, accountability, and audit need a higher bar. A lens on the pillars you already have.
Most of this framework quietly assumes AI that answers: it drafts, summarizes, suggests, and a person decides what to do next. Agentic AI is different. It acts, it books the room, sends the email, updates the record, moves the money, and chains several steps together to reach a goal you set once. That shift, from a tool you operate to a system that operates on your behalf, is where existing assumptions about oversight, accountability, and audit quietly break. This page is a lens, not a new pillar: it stresses the pillars you already have and shows where agentic use needs a higher bar.
The distinction that matters isn't how smart the model is, it's whether a human stands between the output and the consequence.
Produces an output, text, an analysis, a recommendation. A person reviews it and chooses whether to act. The human is the gate.
Takes the action itself, often several in sequence, using tools and system access to reach a goal. The human may only see the result. The gate has moved, or gone.
What quietly breaks
Agentic use doesn't need new values, it needs the existing ones enforced at a point where a human is no longer in the loop by default. These are the assumptions that quietly fail.
Accountability
P7Auditability
P8Data & system access
P4Failure blast radius
P8The autonomy ladder
Autonomy isn't on or off, it's a ladder. Naming the rung an AI use sits on is the single most useful move in governing it, because the required controls rise with each step. Place a use on the lowest rung that still delivers the value.
Suggest
Proposes an option; a person does everything.Draft for approval
Prepares the action fully, but nothing happens until a person approves it.Act with confirmation
Executes routine steps, but pauses for explicit sign-off on consequential ones.Act within bounds
Operates autonomously inside pre-set limits, scope, spend, record types, and escalates anything outside them.Fully autonomous
Pursues a goal end-to-end with no routine human checkpoint.The ladder is a governance tool, not a maturity goal. Higher rungs are not better, they're riskier. The right rung is the lowest one that does the job.
Guardrails, mapped to your pillars
The controls that make higher rungs safe aren't new inventions, they're your existing pillars, applied at the point of action. Each maps to where it already lives in the framework.
Scoped permissions
Give the agent the narrowest system access and credentials that let it do its job, and treat it as a named identity, not a shared key.
Pillar 4 · Governance, risk & dataSpend & action limits
Hard caps on what it can do without escalation, dollars, number of records touched, messages sent, actions per run.
Pillar 8 · Implementation & operationsReversibility & kill-switch
Prefer actions that can be undone; make sure a human can halt the agent immediately and roll back what it did.
Pillar 8 · Implementation & operationsFull action logging
Log the whole chain, every step, tool call, and decision, so any outcome can be reconstructed and audited later.
Pillar 8 · Implementation & operationsEscalation thresholds
Define in advance what forces a human checkpoint, and route it to a named, accountable person, not a queue no one watches.
Pillar 7 · Roles & responsibilitiesNamed accountability
A specific person owns the agent's actions and answers for them, decided before it's deployed, not discovered after an incident.
Pillar 7 · Roles & responsibilitiesRight-sizing it: campus scenarios
What right-sizing looks like in practice. The point of each is the rung and the fence, not the technology.
A student-advising agent
An agent that can answer student questions and take actions, registering for a workshop, flagging an advisor, adjusting a plan.
Rung 3, act with confirmation. It can book a workshop seat on its own (low stakes, reversible) but must route anything touching a student's academic record or standing to a named human advisor. Every action logged; the student always told when they're talking to an agent.
Letting it change enrollment or academic plans autonomously, high stakes, hard to reverse, and directly affecting a student's record.
An operations / procurement agent
An agent that handles routine back-office tasks, drafting POs, reconciling invoices, chasing approvals.
Rung 4, act within bounds. Autonomous under a hard spend cap and only for pre-approved vendors and categories; anything above the cap or off-list escalates to a named budget owner. Full audit trail sized to survive a records request.
An open-ended spend authority with no per-action cap, one bad loop can commit real money across many transactions before anyone looks.
A communications agent
An agent that drafts and sends routine messages to students or staff.
Rung 2–3. Drafts freely; sends automatically only for a narrow, pre-approved class of routine notices; anything sensitive, unusual, or to a large audience waits for human sign-off.
Autonomous send to large audiences, a single templating or targeting error reaches thousands before it can be caught.