Authority boundaries
Actions are classified by consequence. A role cannot lower the category of an action through clever wording.
Worker governance
A worker needs written limits, cost controls, approval rules, an audit trail, and a clear way to stop and ask.
The current Stromation system uses these concepts in its own operation and in role design.
Actions are classified by consequence. A role cannot lower the category of an action through clever wording.
Work runs inside per-run limits and broader spending ceilings. A worker cannot raise its own budget.
Protected actions stop for approval. Silence is not treated as consent.
Sessions record material actions, results, costs, and failures so work can be reviewed.
A blocked worker names what it needs and why instead of guessing or expanding its own authority.
Least privilege, public and private data boundaries, and role-specific prohibitions constrain operation.
Every meaningful action should land in a category a customer can understand.
The action is within the role, reversible where required, inside budget, and supported by an assigned capability.
The action carries higher consequence, new access, legal commitment, material spend, or a protected decision.
The action conflicts with law, customer policy, company policy, or the explicit boundary of the role.
Transparency does not require exposing private reasoning, customer data, or secrets.
The browser reads curated public state and public events. Missing data remains unknown.
Inspect the operating recordThe discovery process maps what the role can do, what must stop for approval, and what will never be allowed.