# Autonomy tiers

> How much an agent may do without a person is earned on evidence, one rung at a time, with sign-off from the people who carry the risk. An agent nobody has graded is an intern.

Source: https://immiscible.fly.dev/docs/concepts/autonomy-tiers

Mandates say what an agent may do. Its tier says how much of that it may do **alone**. A tier can only turn an `allow` into a question; it never turns a question or a refusal into an `allow`.

## The four tiers

| Tier | Says | Pays alone up to | Releases data alone | Records per action, alone / at most |
|---|---|---|---|---|
| `intern` | Prepares the work. A person signs off every payment, data release and outside action | nothing | no | 0 / 1,000 |
| `junior` | Handles small, routine work alone. Bigger payments and any data release go to a person | £50 | no | 100 / 10,000 |
| `senior` | Trusted with everyday payments and releases inside its mandates. Large ones go to a person | £1,000 | yes | 1,000 / 100,000 |
| `principal` | Works inside its mandates without routine sign-off. Its mandates are its only limits | no line | yes | no line |

The money lines are held in pounds and converted for other currencies at a reference rate; a currency with no reference rate is checked by a person at every tier below principal. Records above the "alone" figure are asked about; above the "at most" figure they are refused (`volume_hard_limit`).

New agents start at the workspace's **starting tier**, `intern` unless an owner chose `junior` on the record (with colleagues in the workspace, a second owner confirms). A [service token](https://immiscible.fly.dev/docs/api/authentication.md#service-tokens) registering agents can never ask for more.

## Earning the next rung

Promotion is one step at a time, and only when the evidence is there:

| To | Clean decisions | Days of history | Days without an incident | Sign-offs |
|---|---|---|---|---|
| `junior` | 20 | 7 | 7 | business |
| `senior` | 150 | 30 | 30 | business, security |
| `principal` | 1,000 | 90 | 90 | business, security, legal |

An agent refused more than 10% of the time since its last change of tier is not ready: an agent that is refused often is probing, or doing the wrong job. The console shows exactly what is missing ("12 more clean decisions; sign-off from security").

### Separation of duties

- Nobody promotes an agent that acts for them.
- Whoever signed off a promotion does not also make it.
- Auditors check sign-offs; they do not give them.
- A sign-off is for the promotion in front of it, and lapses after 30 days.

### Break-glass

An owner can promote without the evidence, with a reason of at least a sentence. With anyone else in the workspace it is a proposal a **different** owner confirms within seven days, and no agent is overridden twice in a week. It is still one rung: break-glass is for a rung, not the ladder.

## Losing it

Demotion needs no evidence and takes effect at once. It also happens without anyone choosing it:

- an access profile not [recertified](https://immiscible.fly.dev/docs/guides/traces-and-reviews.md#recertification) by its due date demotes the agent to intern and freezes it;
- a review verdict of `incident` freezes the agent under an incident hold.

## Standing

Every agent carries its standing: the **sponsor** who answers for it, its **purpose** in a sentence, the **kill owner** who may stop it, and when its **assignment** ends (at most 366 days, then someone renews it). The people named must be members of the workspace.

```bash
curl -X PATCH "https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/agents/agt_4f2c91a7/standing" \
  -H "cookie: __Host-sid=$IMMISCIBLE_SESSION" -H "x-immiscible-csrf: 1" \
  -H "content-type: application/json" \
  -d '{ "sponsor": "cfo@acme.example", "purpose": "Pays approved supplier invoices", "killOwner": "secops@acme.example", "assignmentEndsAt": "2027-01-31T00:00:00Z" }'
```

Every change of standing and tier is a record in the [evidence ledger](https://immiscible.fly.dev/docs/concepts/evidence.md): who sponsored the agent, who signed off its promotion and on what evidence, who demoted it and why. A promotion is a decision about risk, so it leaves the same kind of evidence a payment does.

## API

| Method | Path | |
|---|---|---|
| `GET` | [`/api/w/:wid/agents/:aid/standing`](https://immiscible.fly.dev/docs/api/get-api-w-wid-agents-aid-standing.md) | tier, readiness, sign-offs |
| `PATCH` | [`/api/w/:wid/agents/:aid/standing`](https://immiscible.fly.dev/docs/api/patch-api-w-wid-agents-aid-standing.md) | sponsor, purpose, kill owner, assignment |
| `POST` | [`/api/w/:wid/agents/:aid/signoffs`](https://immiscible.fly.dev/docs/api/post-api-w-wid-agents-aid-signoffs.md) | sign off a promotion |
| `POST` | [`/api/w/:wid/agents/:aid/tier`](https://immiscible.fly.dev/docs/api/post-api-w-wid-agents-aid-tier.md) | promote or demote |
| `GET` | [`/api/w/:wid/governance/scorecard`](https://immiscible.fly.dev/docs/api/get-api-w-wid-governance-scorecard.md) | the signed zero trust scorecard |
