Welles Decision Architecture · GOVERN / TOOD 3

Decision Control for Autonomous Agents

Software is beginning to enter obligations on behalf of companies.

An appropriately connected AI agent can prepare offers, place orders, make commitments to customers, prioritize candidates or change systems. Automation becomes delegation. And delegation requires decision rights.

TOOD is designed as a control layer between technical action and organizational obligation. Technical capability is not a mandate.

Discuss an agent use case

Development status: Reference Architecture / Locally Verified. Local tests do not replace evidence of integration and enforcement in an enterprise system.

TOOD Agent Control

AI agents can plan, decide and act.

Growing autonomy therefore increases not only their usefulness, but also the potential impact of a wrong decision.

TOOD controls more than which action an agent may execute.

TOOD examines:

  • which obligation arises from the decision,
  • whether that obligation is covered by the mandate,
  • where defined limits are exceeded,
  • when a human must take over,
  • and whether the organization can actually sustain the decision.

The possible control decision is:

  • ALLOW
  • ALLOW WITH CONDITIONS
  • HUMAN APPROVAL
  • ESCALATE
  • STOP

The core principle: capability is not a mandate.

The action is not the unit of control.
The obligation is.

This describes the intended control architecture. Operational control requires technical integration, designated owners and evidence of enforcement.

Discuss an Agent Governance Review

The unit of control is the obligation, not the action.

Ten individually permitted orders can exceed a budget together. A customer commitment can bind delivery, capacity and liability. Authorizing an individual tool call is therefore insufficient.

Evidence → Decision → Obligation → Mandate → Execution

  1. Evidence

    Which source supports the basis? What is assumed, missing or outdated?

  2. Decision

    What specific decision is pending? Which alternatives and economic consequences matter?

  3. Obligation

    What promise, payment, delivery or downstream effect arises, including alongside existing obligations?

  4. Mandate

    Who may enter this obligation, within which limits? Who carries it and with which resources?

  5. Execution

    Execute only after the required authorization; record outcomes, deviations and interventions.

The obligation is examined before execution. A decision in the review process is not yet permission to act. Approval, intervention and subsequent outcome review retain explicit owners.

Five outcomes. Explicit consequences for execution.

ALLOW

Execute within a valid mandate when all required checks pass.

ALLOW WITH CONDITIONS

Execute only under explicit conditions verified before execution.

HUMAN APPROVAL

Wait for approval from a named, authorized person. No execution beforehand.

ESCALATE

Refer an unclear or conflicting mandate to the responsible authority; keep the affected action paused.

STOP

Block the affected action. Resumption requires resolved prerequisites and the designated authorization.

An emitted status word is not a control. The execution path must enforce the decision; without valid authorization the affected action must not occur.

Illustrative example · Procurement

The order is within the limit. The obligation may not be.

An agent is tasked with replenishing materials. One order falls below its limit, but several open orders draw on the same budget. The current delivery quantity is also not reliably evidenced.

The review therefore considers source currency, accumulated commitments, the new payment obligation and the mandate. Execution remains paused until the basis and authority are resolved. Previously agreed rules determine whether HUMAN APPROVAL, ESCALATE or STOP applies.

This makes the required authorization and resulting obligation explicit. The example illustrates the logic; it does not demonstrate an implemented integration.

One specific agent. A clearly scoped control engagement.

Together we examine one proposed agent use case: permitted actions, resulting obligations, economic limits, human approvals and stop rules. SOA LUMEN adds the question of who can actually handle exceptions, reviews and operations.

  • A mandate and responsibility map with designated decision-makers.
  • Review rules with the five outcomes and explicit execution conditions.
  • Evidence requirements and test scenarios for approval, escalation, stopping and resumption.

Technical integration and operations are agreed with your IT team or a separately commissioned delivery partner. Only tests of the actual execution path can demonstrate that controls hold during failures or changed conditions. The Agent Governance Review costs €7,900 excluding VAT and typically takes 2–3 weeks. Scope, information access and contributions are agreed before starting; technical integration and operations are excluded.

View Agent Governance Review