Overview
How might we design per-action autonomy so people can trust and act on AI output?
When to use
- Essential for AI coding agents, workflow automation, and productivity assistants where different actions carry different risk profiles and users need calibrated autonomy per capability, not per app.
When to skip
- Single-capability agents where per-action settings duplicate a global toggle.
- Audiences who will never open advanced settings; offer sensible defaults first.
- When the platform cannot enforce different policies per tool call.
Rules
One “Autopilot” switch that silently enables irreversible actions.
Per-action settings buried with no summary of current policy.
Defaults that auto-approve send/delete on first connect.
Policies that drift after model or connector updates without notice.
Evidence
| Product | Implementation |
|---|---|
| Email agents | Auto-draft known threads; approve send to new recipients. |
| Cursor / coding agents | Freer edits in working trees; gated pushes to protected branches. |
| ChatGPT agent mode | Differentiated confirms for browsing vs messaging vs purchases. |
| Enterprise IT bots | Auto-read; approve write to production systems. |