Skip to main content
8 September 2026 · The Hive team
There is a tempting way to deploy an AI agent: give it the credentials, write a good prompt, and let it run. It demos beautifully. It also asks you to trust a system on day one with authority you would not give a new employee in their first month. We think autonomy should be earned the same way it is earned by people — gradually, per task, on evidence — and revocable in an instant. This post explains that model, why it matters, and how to apply it whether or not you use Hive.

Trust is per task, not per agent

The first mistake is to ask “do we trust the agent?” as if trust were one number. You probably trust a new hire to draft an internal note on day one, to email a known supplier after a few weeks, and to issue a refund only after months — if ever without sign-off. AI is no different. The question is not whether the agent is trustworthy; it is whether this kind of action, at this level of risk, has a track record that justifies letting it run without a person. That leads to two ideas that do most of the work:
  • Blast radius — how much harm an action could do if it were wrong. In Hive this runs from B0 (invisible or fully reversible, like writing a draft) to B4 (money, legal or irreversible, like issuing a refund). See Autonomy and blast radius.
  • The autonomy ladder — the level of independence an action type currently has.

The ladder

Hive uses five rungs. You can borrow them for any agent system.
  1. Shadow. The agent decides what it would do and records it, but does nothing. This is where proof comes from: you can compare what it would have done with what your team actually did, at zero risk.
  2. Suggest. The agent proposes the action and a person carries it out, or asks the agent to.
  3. Approve each. The agent prepares the exact action — the recipient, the amount, the message — and runs it only after a person approves that specific proposal.
  4. Auto in limits. The agent runs the action on its own, but only inside hard ceilings: a per-action amount, a spending cap per window, a rate cap, a confidence threshold and a blast-radius threshold. Anything outside the limits drops back to approval.
  5. Autonomous. Reserved for routine, low-risk actions with a long clean record.
Two rules sit above the ladder regardless of where an action type is:
  • The highest-risk actions always ask. In Hive, B4 actions and anything irreversible require a human approval every time, as do B3 actions below a high-confidence threshold. No setting turns that off.
  • A kill switch beats everything. One control halts every autonomous action and approval across the workspace, and it survives restarts. See Safety and control.

Who moves an action up the ladder?

Not the model. The most important design choice in an agent system is where the decision to act is made. If the language model decides whether its own action is safe to run, you have handed your controls to the component most likely to be wrong in surprising ways — and most exposed to instructions hidden in an email or a document it reads. In Hive, the model proposes and a deterministic policy disposes. The policy looks at the action type’s rung, the blast radius, the amount, confidence and budgets, and returns one of three outcomes: run it, ask a person, or only simulate it. The model never holds credentials; an isolated executor does. Promotion is also a human decision. When your team approves the same kind of suggestion three times within 30 days, Hive offers to automate it. Accepting creates an active rule straight away, so matching actions start running on their own, and the promotion lifts them no higher than Auto in limits. When someone denies a proposal, Hive proposes an exception rule for that shape of action; once it is promoted, that shape is no longer auto-run. You can see and manage these in Learned behaviours.

Why this is faster, not slower

Earned autonomy can sound like a brake. In practice it is what lets you move quickly.
  • You can switch it on today. Starting in shadow and approval means there is no big-bang risk assessment before the first useful thing happens. Your team sees value — caught problems, prepared drafts — in the first week.
  • Approvals get faster as proposals get better. A good approval screen shows what will happen, the evidence, the blast radius and what happens if you do nothing. Deciding takes seconds. See Review and approve.
  • Mistakes stay small. When something does go wrong at the approval stage, a person catches it. When something goes wrong inside limits, the limits bound the damage, and the audit trail plus undo make it recoverable.
  • The record builds itself. Every decision is logged. When you want to promote an action type, you are looking at evidence, not a hunch.

A practical checklist

If you are deploying agents — with Hive or anything else — these questions are worth answering explicitly:
  1. List the actions, not the agents. For each action the agent can take, write down its blast radius and whether it is reversible, compensatable or irreversible.
  2. Start everything that touches the outside world at approval or below. Drafts and internal notes can move faster; external messages and money should not.
  3. Put hard ceilings in code, not in the prompt. Spend caps and rate limits belong in a policy layer the model cannot talk its way around.
  4. Bind approvals to exact parameters. Approving “send the reminder” should not also approve a different recipient or amount. Hive binds each approval to a hash of the exact parameters and expires it after seven days.
  5. Make denial teach. A “no” should narrow future proposals, not just close a ticket.
  6. Rehearse the stop. Know who can engage the kill switch and what happens when they do.

The point

Agents that start with full permission are fragile: one bad week and the whole programme is paused. Agents that earn permission per task accumulate trust the way good colleagues do — and that is what lets them take on more.

Autonomy and blast radius

How Hive’s ladder and policy gate work in detail.

Approvals before automation

Designing approvals people can decide in seconds.