What Information Should Be Gathered Before Authorising an AI Agent?
Before an AI agent is authorised to act in a live environment, an organisation needs to gather specific information. Without it, the agent is being given authority blind. Karvin's AI Authority Readiness Assessment evaluates 19 dimensions across five groups.
Context: business purpose (what the AI is for and why), owner (named individual accountable), decision owner (who owns the decisions the agent produces), agent or model (which AI is being deployed), and model version (specific version, where relevant).
Access: systems accessed (which enterprise systems the agent reaches), tools (which tools it may invoke), and data accessed (what data it may read or process). An agent that can access the finance system and customer PII has a very different risk profile to one that summarises internal documents.
Authority: permitted actions (what the agent is explicitly allowed to do), prohibited actions (what it is explicitly not allowed to do), financial thresholds (spend or value limits per action), and approval requirements (which actions need human approval first).
Conditions: geographic restrictions (where the agent may or may not operate), operating conditions (context, time and risk conditions that apply), escalation (what happens when the agent cannot proceed), and failure behaviour (what the agent does when something goes wrong).
Evidence: authority revocation (how the agent's authority is withdrawn), evidence (what is recorded for each decision and action), and audit requirements (what auditors and regulators need to see).
Each dimension is assessed and translated into implementable requirements. Context and access dimensions drive ServiceNow governance configuration: AI inventory, risk classification, ownership and controls. Authority and conditions dimensions drive VORTIQ-X runtime authority boundaries: permitted and prohibited actions, financial limits, approval routing and context-aware rules.
The result is a specification that is directly actionable. The agent is not authorised until every dimension is answered, and the answers are translated into enforceable controls.
Karvin's AI Authority Readiness Assessment gathers and structures this information. If you are authorising an AI use case, start with the assessment.
Book a Workflow Review →