ALLOW
Execute within a valid mandate when all required checks pass.
Welles Decision Architecture · GOVERN / TOOD 3
Software is beginning to enter obligations on behalf of companies.
An appropriately connected AI agent can prepare offers, place orders, make commitments to customers, prioritize candidates or change systems. Automation becomes delegation. And delegation requires decision rights.
TOOD is designed as a control layer between technical action and organizational obligation. Technical capability is not a mandate.
Discuss an agent use caseDevelopment status: Reference Architecture / Locally Verified. Local tests do not replace evidence of integration and enforcement in an enterprise system.
AI agents can plan, decide and act.
Growing autonomy therefore increases not only their usefulness, but also the potential impact of a wrong decision.
TOOD controls more than which action an agent may execute.
The core principle: capability is not a mandate.
The action is not the unit of control.
The obligation is.
This describes the intended control architecture. Operational control requires technical integration, designated owners and evidence of enforcement.
Discuss an Agent Governance ReviewTen individually permitted orders can exceed a budget together. A customer commitment can bind delivery, capacity and liability. Authorizing an individual tool call is therefore insufficient.
Which source supports the basis? What is assumed, missing or outdated?
What specific decision is pending? Which alternatives and economic consequences matter?
What promise, payment, delivery or downstream effect arises, including alongside existing obligations?
Who may enter this obligation, within which limits? Who carries it and with which resources?
Execute only after the required authorization; record outcomes, deviations and interventions.
The obligation is examined before execution. A decision in the review process is not yet permission to act. Approval, intervention and subsequent outcome review retain explicit owners.
Execute within a valid mandate when all required checks pass.
Execute only under explicit conditions verified before execution.
Wait for approval from a named, authorized person. No execution beforehand.
Refer an unclear or conflicting mandate to the responsible authority; keep the affected action paused.
Block the affected action. Resumption requires resolved prerequisites and the designated authorization.
An emitted status word is not a control. The execution path must enforce the decision; without valid authorization the affected action must not occur.
Illustrative example · Procurement
An agent is tasked with replenishing materials. One order falls below its limit, but several open orders draw on the same budget. The current delivery quantity is also not reliably evidenced.
The review therefore considers source currency, accumulated commitments, the new payment obligation and the mandate. Execution remains paused until the basis and authority are resolved. Previously agreed rules determine whether HUMAN APPROVAL, ESCALATE or STOP applies.
This makes the required authorization and resulting obligation explicit. The example illustrates the logic; it does not demonstrate an implemented integration.
Together we examine one proposed agent use case: permitted actions, resulting obligations, economic limits, human approvals and stop rules. SOA LUMEN adds the question of who can actually handle exceptions, reviews and operations.
Technical integration and operations are agreed with your IT team or a separately commissioned delivery partner. Only tests of the actual execution path can demonstrate that controls hold during failures or changed conditions. The Agent Governance Review costs €7,900 excluding VAT and typically takes 2–3 weeks. Scope, information access and contributions are agreed before starting; technical integration and operations are excluded.
View Agent Governance Review