Glossary
Autonomy level
The autonomy level is how much a system may do before it has to ask, and it is the single setting that moves both the value and the risk of running one.
In plain terms
How far it gets to go on its own. At one end it proposes and waits. At the other it acts and tells you afterwards, if it tells you at all. Everything people like about this technology and everything that worries them come from the same dial, which is why arguing about it in general tends to go nowhere until somebody says where the dial is set.
Why it matters
Because the benefit and the exposure are the same movement, and treating them as separate conversations produces incoherent decisions. Asking whether to permit agents is unanswerable. Asking what this one may do without checking is answerable, has an owner, and is the question a review will actually put to you.
How it works
It is a range rather than a switch, and products place themselves along it differently. Proposing and waiting, acting within a stated boundary and reporting, and acting freely until something stops it are three quite different products sold under the same word. Which one you have is worth establishing before any comparison of capability, because it decides what the capability means.
The permission that matters is not the same as the permission that gets discussed. Reading widely is usually fine. Acting is where it changes, and the sharp line falls at what cannot be undone: sending, paying, deleting, publishing, committing. An agent free to read the entire estate and forbidden those five is a different proposition from one with the reverse settings.
Vendors set a default and the default is frequently what an organisation ends up running, because nobody was asked to choose. That makes the shipped setting a decision somebody else made about your risk, and it is one of the few product settings where the sensible move is to look at it deliberately rather than discovering it during an incident.
It is earned rather than declared, which the platforms themselves say. One describes always-on autonomy as something earned, with supervision preceding trust and usage climbing with ambition. That framing is useful because it makes the dial a thing you move over time on evidence, rather than a value you pick once from a dropdown.
Cost tracks it, which is the part that surprises people who thought about risk and not about the bill. More autonomy means more steps taken without anybody deciding whether each was worth taking, and on metered pricing every one of those is billable. An agent working unsupervised for an hour has been spending for an hour.
The dial, and what changes as it turns
Seen in the wild
A general agent briefed like a contractor and reviewed on what comes back, rather than steered turn by turn, whose own documentation warns that polished unattended output is the trap.
ManusA platform stating that always-on autonomy is earned, that supervision precedes trust, and that usage climbs with ambition.
Relevance AIAgents that run on triggers rather than waiting to be asked, where the rules they must follow are set when the agent is described.
Lindy
Common misconceptions
People assume
Higher autonomy is the goal and lower settings are training wheels.
In fact
The right setting is a property of the task rather than a stage of maturity. Work that is repetitive, bounded and cheap to undo suits a high setting permanently. Work that is irreversible suits a low one permanently, however long it has been running well, because the thing that makes it risky does not improve with familiarity.
People assume
Setting it is a technical decision.
In fact
It is a decision about what your organisation is willing to have happen without a person present, which is why it sits badly with whoever configured the tool. The people who should answer it are the ones who would have to explain the result, and they are usually not in the room when the default is accepted.
Telling them apart
Autonomy level vs Human in the loop
Autonomy level
How much the agent may do before asking.
The arrangement that puts a person at the asking point.
One is the setting, the other is what the setting produces. A loop with nobody actually reading is a setting pretending to be an arrangement.
Questions
- What is the useful way to decide it?
- By what the action costs to undo rather than by how much the agent is trusted. Reversible work can sit high because a mistake is absorbed by ordinary correction. Irreversible work sits low regardless of track record, since the reason it is risky is a property of the action and not of the agent doing it.
- Should it be one setting for everything?
- Rarely, and a single global value is the commonest reason a sensible policy gets routed around. One dial covering both drafting and payment either blocks the drafting or permits the payment. Where products allow it to vary by action, that is usually the difference between a rule people follow and one they work around.
- Does more autonomy save time?
- It saves attention and spends money, which is a real trade rather than a free one. Steps taken without anybody deciding they were worth taking are still billed, so an agent working unsupervised has been consuming for the whole period. That is the same property that makes it useful, seen from the invoice.
- How would we know it is set wrongly?
- Too low shows up as people bypassing the tool because approving everything is slower than doing the work. Too high shows up late, as something that happened which nobody would have approved. Only the first complains, which means the pressure over time runs in one direction.
Key takeaways
- A range, not a switch, and three quite different products are sold under the word.
- The line that matters falls at what cannot be undone, not at what can be read.
- The shipped default is a decision somebody else made about your risk.
- Earned on evidence rather than declared, which the platforms say themselves.
- More autonomy spends money as well as saving attention.
Tools that use this
- Manus
Briefed like a contractor, with polished unattended output named as the trap.
- Relevance AI
Autonomy earned, supervision before trust, usage climbing with ambition.
- Lindy
Trigger-run agents with the rules set when the agent is described.
Last checked July 2026