Step 03 — Govern

What should an AI agent be allowed to do on its own?

A concrete model for answering that question, one task at a time, before anything is allowed to act inside a real business. This is Govern, step three of the Mochlos methodology, expanded into what actually has to be decided.

One owner · One autonomy class · Ask, not guess · Append-only record

An agent without a declared boundary is not faster. It is unauditable.

Every operator who looks seriously at AI agents arrives at the same question before any other: fine, but what is it actually allowed to do without me? Most pitches move past this quickly, because the honest answer is less exciting than the demo — the agent can do less than it looks like it can, and the parts it can't do unsupervised are exactly the parts that matter.

The model below is how we answer that question for a real operation, not for a slide. It doesn't start from what the technology is capable of. It starts from what a task is worth getting wrong, and works backward to how much autonomy that task has earned.

One owner, one class — no exceptions

Every task in the operation gets exactly one owner and exactly one autonomy class. Not a department — one person. Not "usually automatic" — one of three fixed classes, decided in advance. Ambiguity here is where the failures we've seen actually start, and it's rarely the agent doing something wrong. It's that nobody decided in advance what right was supposed to look like.

Class 01

Runs autonomously

The bookkeeping of the process — creating a record, updating a status, filing a finished document where it belongs. Work where a mistake is cheap to notice and cheap to undo, so it doesn't need a human's attention to keep moving.

Class 02

Drafted, human approves

Anything carrying legal, financial, or compliance weight. The agent prepares it completely and accurately, then stops. A human decides whether it goes out. Nothing in this class leaves on its own.

Class 03

Never autonomous, by design

Decisions that belong to a person, not a system — terms, compensation, employment status, anything with someone's name and consequence attached. The agent only ever reads what a human has already decided. It never writes the decision itself.

The default failure mode is ask, not guess

That default is fixed, and it's the same across all three classes: when information is missing, or a system the task depends on is unreachable, the task stops and waits. It does not proceed on an assumption, and it does not fail silently by skipping the step and moving on regardless. An agent that guesses when it should have asked is worse than one that does nothing — a wrong guess looks like progress right up until someone discovers it wasn't.

The record that makes it checkable

Every action — an agent's or a human's — writes to a permanent, append-only record. Corrections are new entries, never rewrites of the old ones. That's what turns "we think it's fine" into a specific, checkable answer to what happened, when, and who signed off on it — reconstructed from the record itself, months later, rather than from whoever happens to remember. A governance model that can't produce that answer on demand isn't governing anything. It's a policy on a page nobody ever checks.

Where this came from This isn't a framework drawn up for a sales page. It's the boundary structure running today inside a governed process at the center of how we operate — every task assigned to exactly one of these three classes, nothing left unowned, nothing assumed to be someone's job by default. See the full sequence it governs →

Why this is the step almost everyone skips

It's the step with the least visible progress to show for it. Wiring an agent to draft a document or update a board is a five-minute demo. Deciding, task by task, which of three classes each one belongs in — and building the stop-and-ask behavior for when it doesn't have enough to proceed — is slow, unglamorous work, and it's easy to defer until "after we see if this works."

That deferral is the expensive mistake. An agent running without a declared boundary isn't faster than one running with one — it's exactly the same speed, minus the one thing that made it safe to leave unattended. The first time something goes wrong, there is no record of what it was allowed to do, no single owner to ask, and no way to tell whether it acted inside its authority or simply got lucky every time before. Fast and unauditable is not a trade worth making.

Where this fits

Govern is step three of five in the Mochlos methodology — Document, Build, Govern, Audit, Improve. It's what makes the build from step two safe to leave running; Audit, step four, is what proves it stayed that way. Read the full methodology →

← Back to Mochlos

Bring us the AI agent decision you don't want to get wrong. We'll tell you directly where the line should sit, and why.

Talk to us