Worker governance

Authority should be visible before autonomy begins.

A worker needs written limits, cost controls, approval rules, an audit trail, and a clear way to stop and ask.

Core controls

Governance is part of the worker.

The current Stromation system uses these concepts in its own operation and in role design.

Authority boundaries

Actions are classified by consequence. A role cannot lower the category of an action through clever wording.

Budgets

Work runs inside per-run limits and broader spending ceilings. A worker cannot raise its own budget.

Approval requirements

Protected actions stop for approval. Silence is not treated as consent.

Auditability

Sessions record material actions, results, costs, and failures so work can be reviewed.

Escalation

A blocked worker names what it needs and why instead of guessing or expanding its own authority.

Safety rules

Least privilege, public and private data boundaries, and role-specific prohibitions constrain operation.

Decision model

Three outcomes at the boundary.

Every meaningful action should land in a category a customer can understand.

Human or owner

Approval required

The action carries higher consequence, new access, legal commitment, material spend, or a protected decision.

Hard stop

Forbidden

The action conflicts with law, customer policy, company policy, or the explicit boundary of the role.

Public proof

The observer also has a boundary.

Transparency does not require exposing private reasoning, customer data, or secrets.

Approved public surfaceStromation Live

The browser reads curated public state and public events. Missing data remains unknown.

Inspect the operating record
  1. PublicObjectives, approved events, costs, status, and public artifacts.
  2. PrivateRaw prompts, secrets, private records, and customer information.
  3. EnforcedThe anonymous browser key has read access only to the public surface.
Design the boundary first

Custom workers begin with authority, not access.

The discovery process maps what the role can do, what must stop for approval, and what will never be allowed.

Request a Custom Build