Cobalt Giraffe Research
Identity, Authority and Autonomy
Three control dimensions for governable enterprise agentic AI
Working conceptual model / research in progress
Agentic AI creates a control problem that goes beyond access management alone.
Once AI systems can interpret requests, retrieve knowledge, invoke tools, delegate work and take consequential actions, the enterprise must govern more than system access.
It must determine:
- who or what is acting
- what it is allowed to do
- how independently it may act
These three dimensions - identity, authority and autonomy - provide a useful control model for governable enterprise agentic AI.
Working conceptual model / research in progressEnlarge SVG (new tab) ↗PNG export (new tab) ↗
Identity - who is acting?
Identity establishes which agent is acting.
That may include a logical agent identity, a runtime or session identity, and the ownership or accountability associated with that agent.
Without reliable identity, the enterprise cannot confidently determine which agent performed an action or reconstruct what happened afterwards.
Authority - what is it allowed to do?
Authority defines what an agent is permitted to do.
That may include access to data, use of tools, invocation of APIs, modification of systems, delegation rights and action limits.
A known identity does not imply unlimited permission.
An agent can be validly identified and still be over-permitted, misused or allowed to act outside its intended role.
Autonomy - how independently may it act?
Autonomy is distinct from both identity and authority.
Two agents may be allowed to access the same tool while operating under different autonomy limits.
One agent may only suggest an action.
Another may prepare an action but require approval.
A third may execute within tightly defined limits.
That makes autonomy a governable architectural property, not just a behavioural preference.
Related, but not interchangeable
Identity, authority and autonomy are connected, but they answer different questions.
Identity asks who is acting.
Authority asks what it may do.
Autonomy asks how independently it may do it.
A governable enterprise agentic architecture needs to evaluate all three together before allowing consequential action.
Control is shaped by policy, risk and evidence
These three dimensions do not operate in isolation.
Policy determines what rules apply.
Risk determines how serious the consequence may be if the agent gets it wrong.
Evidence determines whether the enterprise can reconstruct and justify what happened afterwards.
Where consequences are significant, human approval may also need to remain in the loop.
Different agents, different controls
A research assistant, a customer operations agent and a payment-preparation agent should not be governed in the same way.
They may operate in the same enterprise while having very different identities, permissions and autonomy limits.
That is why agent governance has to be differentiated according to purpose, authority, autonomy and consequence.
The emerging principle
The current working hypothesis is:
Governable enterprise agentic AI depends on three core control dimensions - identity, authority and autonomy - shaped by policy, risk, evidence and human approval.
This is an evolving Cobalt Giraffe research model rather than a claimed universal standard.