| Control | What to Verify |
|---|---|
| Approval gating | Policy-based rules that auto-approve low-risk actions and require human sign-off for high-impact changes |
| Blast-radius caps | Hard limits on the number of hosts, services or regions any autonomous action can affect |
| Kill switch | A global autonomy toggle plus per-agent disablement, effective immediately |
| Dry-run mode | Agents investigate and propose without executing until explicitly promoted |
| Immutable audit trail | Every action logged with actor identity (human or AI), inputs, outputs, timestamps and rollback status |
| Model and data controls | Choice of model tier, support for private or hosted models, and regional restrictions on AI processing |
| Question | What a Strong Answer Includes |
|---|---|
| How does the tool reach a root cause conclusion? | Traceable evidence chain with links to telemetry, changes and tickets |
| What can the tool execute without human approval? | Configurable policy, defined per action type and environment |
| How is the scope of an autonomous action limited? | Enforced caps on hosts, services and regions, not advisory settings |
| How quickly can autonomy be halted? | Immediate global and per-agent stop, with no pending actions completing |
| Where is operational data processed? | Stated regions, customer-controlled residency and private model options |
| How is accuracy measured over time? | Reusable runs, failure analysis and comparison against human baselines |
Experience Governed Autonomy in Your Own Environment