Capability is not
the same as permission.
A system can be technically able to take an action without being authorised to take it. KoLo keeps those two facts apart, so operational control stays explicit rather than emergent.
Autonomy without authority is not intelligence we are willing to deploy.
01 — THE AUTHORITY PRINCIPLE
Most AI incidents are permission failures, not capability failures.
When an automated system causes institutional harm, the cause is rarely that it could not do the task. It is that nobody had decided, in advance and in writing, what it was allowed to do — so capability quietly became permission by default. The gap is filled at runtime by whatever the system happens to be able to reach.
Treating the two as separate facts costs something: every consequential action has to be classified before it can be taken. That cost is the point. An institution that cannot say who authorised an action cannot be said to be in control of it.
Capability is discovered. Permission is granted. A system that confuses them will eventually do something nobody chose.
02 — WHO MAY DO WHAT
Four actors. Four verbs.
Every consequential action in a KoLo deployment resolves to a cell in this table. Nothing acts outside it, and nothing approves its own action.

| Observe | Recommend | Act | Approve | |
|---|---|---|---|---|
| Autonomic system | Defined | Limited | Bounded | Not permitted |
| KoLo agent | Defined | Defined | Policy-bound | Not permitted |
| Human operator | Yes | Yes | Role-based | Defined |
| Accountable authority | Yes | Yes | Yes | Final |
03 — BOUNDED AUTONOMY
What defines the edge of an envelope.
“Bounded” is meaningless unless the bounds are named. Five dimensions define what an autonomous component may do — and each is declared before deployment rather than discovered during an incident.
04 — EVIDENCE AND AUDIT
An action without a record did not happen accountably.
Governance that cannot be inspected afterwards is a claim, not a control. Five properties turn activity into evidence.
The fourth is the one most systems get wrong. Recording that a job ran is not the same as recording that it achieved anything — and a dashboard built on the first will report green through a total failure of the second.
05 — ESCALATION
The conditions that return control to a person.
06 — SOVEREIGNTY
Seven layers, not one server.
Sovereignty is claimed too often on the strength of where a model is hosted. Hosting is one layer of seven.
07 — GOVERNANCE ACROSS DEPLOYMENTS
Authority does not widen with capability.
A deployment that escalates from a local model to a frontier one gains capability. It does not thereby gain permission — the envelope is a property of the institution’s policy, not of the model answering.
08 — TRUST IS OPERATIONAL
Trust has to be inspectable.
Institutional trust cannot rest on a system appearing intelligent. It rests on whether the organisation can see what happened, why, under whose authority and on what evidence.
09 — STATUS AND CLAIM BOUNDARY
What this page does not claim.
The goal is not unrestricted autonomy. It is useful autonomy, operating inside visible authority, evidence and human responsibility.

