Skip to main content

Authority Envelopes

An authority envelope is the autonomy contract for a single actor (agent or user identity). It declares what that actor is allowed to do at the granularity of action types, data classifications, target systems, and risk thresholds — and gives operators a single switch (freeze / thaw) to suspend all of it instantly.

It's the constitution for the actor. Policy rules are the laws; the envelope is what defines the citizen's standing.

Where to find it in the app​

Envelopes live on the agent itself.

Dashboard → Agent Registry → click an agent → Authority & Policy tab.

This is the primary surface. From this tab you can:

  • View the agent's current envelope (autonomy tier, thresholds, allowed data classes, allowed systems, required-approval actions, domain constraints)
  • Edit any of those fields and save
  • Freeze the envelope — a single click that immediately blocks every future action
  • Thaw the envelope — restore the agent to its configured state

A read-only view of an envelope is also available from Dashboard → Risk & Compliance → Identity Reports → open an actor's report — useful when you want to inspect an envelope without the option to change it.

When an action is allowed, blocked, or deferred by the envelope, the Actions & Evidence detail view for that action shows the envelope ID and which envelope gate fired — so you can trace any decision back to the envelope that produced it.

Why envelopes exist​

Policy rules answer "what should happen to this specific detection?"

Envelopes answer "what is this actor allowed to attempt at all?"

The distinction matters because:

  • Speed of containment. When an agent goes rogue, you don't have time to debate which policy rule needs adjusting. You freeze the envelope from the Authority & Policy tab and the agent is contained instantly. Thaw it later when the investigation is done.
  • Defense in depth. Even if a policy rule has a bug, the envelope still blocks anything outside its scope. The two layers cover each other's gaps.
  • Per-actor autonomy levels. Different agents earn different autonomy. A read-only analytics agent and an autonomous billing agent should not share a policy regime — they should share a regime, with different envelopes.

What an envelope contains​

Every field below appears on the Authority & Policy tab. Edit them in the form, click Save, and the envelope is updated atomically.

FieldDescription
ActorThe agent or user identity this envelope governs
Max autonomyHighest autonomy tier allowed: READ_ONLY, APPROVAL_REQUIRED, LIMITED, FULL
Risk tolerance thresholdRisk-score ceiling for any individual action — actions with computed risk above this are denied
Max exposure scoreComposite exposure cap (signal + actor + context) — actions exceeding it require step-up
Allowed data classificationsData classes the actor may access (PUBLIC, INTERNAL, CONFIDENTIAL, RESTRICTED, etc.)
Blocked data classificationsExplicit deny-list of data classes (takes priority over the allow-list)
Allowed systemsSpecific target systems the actor may interact with (by name or URI)
Required-approval actionsAction types that force the DEFER (human-in-the-loop) workflow regardless of risk
Domain constraintsFree-form scope (e.g. "only customers in territory EU")
Frozen stateContainment state — set by Freeze, cleared by Thaw. Shows freeze reason and timestamp.

Autonomy tiers​

The autonomy tier is a ceiling on what kinds of actions the envelope permits. Set it from the Max autonomy dropdown on the Authority & Policy tab.

TierAllowed actions
READ_ONLYReads only — every WRITE / FINANCIAL / SYSTEM / COMMUNICATION action is blocked
APPROVAL_REQUIREDAll non-read actions DEFER to human approval. Reads pass through.
LIMITEDHigh-risk action types (FINANCIAL, SYSTEM, EXTERNAL_COMM) require approval; routine actions pass
FULLThe envelope no longer gates action types — only the risk thresholds and data classifications matter

The tier is a ceiling, not a free pass. Even at FULL, listing an action type in the Required-approval actions field still forces approval on those specific actions.

Freeze and thaw​

The envelope is the kill switch. Freeze and Thaw are the two prominent buttons at the top of the Authority & Policy tab.

Freeze​

Click Freeze, enter a short reason (e.g. "Suspicious tool-call pattern at 03:14 UTC — investigating"), and confirm.

After freeze:

  • Every action gate evaluation against this actor returns BLOCK.
  • All open DEFER workflows for the actor in Actions & Evidence → Pending Approvals are auto-rejected.
  • The actor's trust score is unaffected (freeze is about containment, not trust).
  • A governance history record is written with your reason and the timestamp — visible in the agent's History tab.

Freeze is immediate and total. Use it for the "we just saw an exfiltration pattern, stop everything" case.

Thaw​

Click Thaw to restore the actor to the envelope's configured state. The freeze reason stays in governance history for audit. The actor's trust score and violation count are not changed by the thaw.

Updating envelope fields​

To change a threshold or scope, edit the corresponding field on the Authority & Policy tab and click Save. The change is applied immediately to the next gate evaluation.

Frozen state is not edited through the form — always use the Freeze / Thaw buttons so the reason and audit trail are recorded.

How envelopes interact with the enforcement chain​

The Autonomy check in the enforcement chain evaluates the envelope on every tool call:

  1. Is the envelope frozen? → BLOCK.
  2. Is the action type allowed under Max autonomy? → If not, BLOCK.
  3. Is the target data classification in Allowed data classifications and not in Blocked? → If not, BLOCK.
  4. Is the target system in Allowed systems? → If not, BLOCK.
  5. Is the action type in Required-approval actions? → If yes, DEFER.
  6. Does the computed risk exceed Risk tolerance threshold? → BLOCK.
  7. Does the composite exposure exceed Max exposure score? → DEFER (step-up).
  8. Otherwise → fall through to the next gate.

Envelopes do not replace policy rules — they augment them. Every envelope-blocked action still produces a governance history record and contributes to the actor's risk profile.

When an envelope is missing​

If an actor has no envelope configured, the engine uses a permissive default — gates rely on policy rules alone. Setting an envelope is opt-in per actor, but highly recommended for any actor with FINANCIAL or SYSTEM authority.

You can spot actors without envelopes by filtering the Agent Registry by No envelope.

Removing an envelope​

The Authority & Policy tab has a Remove envelope action. Use it only when you genuinely want to lift the contract — most of the time you want Freeze (temporary) or just edit the fields (adjust) instead.

Next steps​