Guarded Automation: Agents That Run Operations Module 6 · Own It

The Autonomy Bill

Last reviewed · content updated

Advanced

What you'll learn

~15 min
  • List the incremental cost lines a guarded agent adds, and name the two adjacent bills this one is not
  • Explain which approval-load inputs the current receipt log does and does not record, and leave approver hours reader-supplied
  • Explain why the storm night's one-minute call spacing is not a staffing model
ℹLeadership brief

What it is: the incremental cost of guarding one agent — the gateway and policy work, the approver hours an ask-class action actually spends, the verifiers and compensators an engineer writes once and maintains after, the halt drill, and the receipt storage this training’s five modules already built.

What it buys: a bill leadership can fund or push back on, priced from the same agent’s own receipt log rather than from a vendor demo or a guessed weekly allowance.

What to fund: the approver hours the log actually shows for classes routed to ask, the drill cadence 4.3 set, and the storage and anchoring a receipt chain needs to outlive the agent that wrote it — never a total borrowed from a different training’s bill.

Before the detail — Artifact: the autonomy bill, costed from the agent’s own log. Status of what follows: reusable guidance — no standard prices a guarded agent for you.

Prompt first: draft the bill, leave every hour blank

Here is MU-AI-011's action register [paste Lesson 1.3's table: verb /
class / autonomy level] and our own receipts_query.py --stats output
for the last full week [paste, or NOT YET LOGGED].
Draft the AUTONOMY BILL, one line per input, each a bracket I fill:
- gateway and policy engineering: [H_build] hours to stand up the
guard, the envelope file, and its bypass tests; [H_maint] hours
per month to keep the policy current as tools change
- approver hours: for each action class actually routed to `ask`
(not every class - read this off the register), [N_per_week]
approvals per week x [H_per_approval] hours x [approver rate]
- verifiers and compensators: [H_verify] hours to write and
maintain one independent post-condition check per mutating tool;
[H_compensate] hours per declared inverse
- halt drills: [H_drill] hours per drill x [drills_per_year], at
4.3's cadence
- receipt storage and anchoring: [cost_storage] to retain the
chain at our retention window; [cost_anchor] for whatever
anchoring cadence we choose
Invent no number for any bracket. Where our log has not run long
enough to answer one, write NOT YET LOGGED - never an average from
somewhere else.

An agent can total a spreadsheet from any numbers it is handed; only the receipt log and the person who staffs approvals know which bracket is a real weekly count and which is a guess dressed as one. Writing NOT YET LOGGED keeps an unsupported estimate from becoming contract risk.

What this bill prices, and what it does not

This bill prices the incremental cost of guarding one agent — the machinery this training’s first five modules built, priced out line by line: the envelope, the approvals, the verifiers and compensators, the kill switch’s drill, and the receipt chain. It is not a headcount request for running MU-AI-011 unguarded, because there is no such option this training offers — running it unguarded is the release AI Assurance 4.3 (a separate training in this series) has not approved.

Two adjacent bills price different things, and this one fences against both in one line each. AI Assurance 6.3’s bill: reviewer hours, ten systems — that sheet prices the reviewer bench that reads release-decision records across a whole portfolio, not the gateway in front of one agent. Operating in Production 6.2’s bill: on-call seats, one page — that sheet prices the rotation that answers an incident once it exists, not the machinery built to keep an agent from causing one. A leader who folds any of the three into the others is funding one line twice and leaving another at zero.

Approver hours: the log already answers this

The register (1.3) routes each action class to a decision — allow, ask, or a standing deny — and only the ask classes cost an approver’s time. In MU-AI-011’s own envelope, draft_work_order and update_work_order_priority are allow: no approver reads them. pre_position_crew (compensable) and send_dispatch_notice (irreversible, two people) are ask: every attempt costs an approver some time, not zero. Pricing “approver hours” against the whole register instead of the ask rows alone is the single most common way this bill overstates itself.

receipts_query.py --stats counts receipt rows, not approval events or elapsed review time. In this run, ask=1 counts only the action that cleared approval; the one-signature refusal is stored as deny, while the 14-crew request never reached approval. Therefore neither --action pre_position_crew --stats nor by decision ask=1 is an approver-hours count. Until the query exposes accepted and rejected approval presentations separately, write NOT YET LOGGED for approval volume; handling duration remains reader-supplied.

Verifiers, compensators, and the drill

Every mutating tool in the envelope needs an independent post-condition check (3.2’s subject) and, where the class allows it, a declared inverse (3.3’s subject) — both are engineering hours a team writes once and then maintains as the target system changes underneath. Neither cost belongs to the agent’s runtime; both belong to this bill, because a verifier or a compensator that nobody funded to maintain is one silent target-system change away from the false-success clamp 3.2 already named.

The halt drill (4.3) is a cost with a cadence, not a one-time build: rehearsing report-only, then enforce, and measuring time-to-halt is staffing time repeated on a schedule the drill’s own owner sets, and it belongs on this bill at that cadence — never priced once and forgotten. Receipt storage and anchoring close the list: retaining a growing, hash-chained log and running whatever anchoring cadence the organization picks both cost something, and neither figure exists in this substrate’s committed files, because storage pricing is an environment fact this training does not carry.

The storm night’s clock is not a cost model

The nine-call run in the next lesson moves through a full night’s worth of decisions one minute apart — a scripted cadence built so a classroom can watch every step, not a claim about how often a real crew-dispatch agent acts or how long an approver actually takes to read a card. Multiplying that spacing into a staffing number invents an hour this training never claimed. The gate’s committed timings prove the guard’s steps execute in the right order and halt on command; they answer nothing about cost, and this bill’s only honest inputs are the brackets the reader supplies from a real log, a real approver, and a real storage bill.

Treating a demonstration’s clock as a cost line is the fastest way to turn a defensible bill into one the first auditor throws out.

Stop and escalate when a bracket in the prompt above cannot be filled honestly — no receipt log old enough to count approvals, no named engineer maintaining a verifier, no answer for storage cost. Only the agent’s named owner (Distribution Operations, Mgr. L. Tran, per 1.1) can decide whether to fund the missing line or hold the agent at its current autonomy level until it is answered.

KNOWLEDGE CHECK

A budget proposal lists only a gateway-license quote and treats the storm transcript's scripted call spacing as the approver-staffing rate. What is wrong with this bill?

Key takeaway

The autonomy bill prices what guarding MU-AI-011 costs beyond running it at all: gateway and policy engineering, approver hours reader-supplied for the classes that actually route to ask (the log names which classes those are; it does not yet total the hours), verifier and compensator maintenance, the halt drill’s cadence, and receipt storage and anchoring — every line supplied by the reader’s own log, never invented and never folded into an adjacent portfolio-review or on-call bill. The storm night’s own clock proves the guard’s order of operations, not a staffing rate. The next lesson turns from what this guard costs to what it has to show before an action class earns a higher level.

LEADERSHIP DECISION fund the guard's incremental lines from the
agent's own receipt log, distinct from the
assurance bill and the operations bill
PRACTITIONER ACTION name the classes routed to ask from the
register, not the log's action counts; write
NOT YET LOGGED for approver hours until then
SUCCESS MEASURE zero bill lines sourced from a demonstration's
timing instead of a real log or a named
engineer - audit finding avoided
Search lessons