Governance, accountability and truth
The agent is not the system. Humans must be the loop.
MOM-505 defines authority, MOM-305 contains what goes wrong, and MOM-405 keeps the evidence.
Designed before the action, not argued after it
Agents act at machine speed. The authority they act under, the thresholds that stop them and the person who answers for the outcome have to exist before the first action. BlueHour thesis
- Defined authority: who may decide what, within which limits
- Approval thresholds and escalation: above a limit, a named person decides
- Exception handling: what happens when the rules do not fit
- Containment and recovery: stop the smallest scope that works; keep the rest running
- Audit evidence: what was known, which rule applied, who decided
- Human accountability: a named owner for every consequential outcome
Context
NIST’s AI Risk Management Framework organizes AI risk management into four functions: Govern, Map, Measure and Manage. Sourced research Source
MOMs are designed to give governance an operating home inside each capability. This site does not claim conformance with any framework.
Decision authority
What an agent may do, what needs a person, what is never permitted
In practice
A consequential recommendation, and a boundary violation
Both examples show conceptual controls for illustration. The simulator is not a production-grade security system, and these are not deployed or validated controls.
The governance MOMs
MOM-505 · Governance & AccountabilityWho may decide what, at what threshold, and who answers for the outcome.Explore →
MOM-305 · Operating RiskWhat to stop, what must keep running, who decides, and how the enterprise recovers.Explore →
MOM-405 · Truth PreservationA verifiable record of what was known, which rule applied and who decided.Explore →
