The framework

Authority-
Centered
Enforcement™

A governance framework for delegated authority

Capability tells you what an AI agent can do. ACE helps you decide what it should be allowed to do on your behalf.

Under what conditions that authority may be exercised, and how it stays enforceable as the agent acts. ACE helps organizations scale autonomous AI without surrendering accountability, judgment, or control.

The central question

What authority have we delegated, under what conditions may it be exercised, and how do we remain in control as those conditions change?

AI Governance Is an Organizational Capability

Governing AI agents takes more than technology, and more than policy. It takes three kinds of capability, and they only work when they work together.

Organizational

Defines accountability, decision rights, risk appetite, and where human judgment belongs.

Operational

Turns those choices into workflows, approvals, escalation paths, evidence requirements, and repeatable practices.

Technical

Enforces those choices through identity, permissions, observability, runtime controls, and mechanisms to pause, narrow, or revoke authority.

Organizational
LeadershipDecision rightsAccountabilityRisk appetite
Operational
PoliciesApprovalsOversightEscalation
Technical
IdentityPermissionsRuntime controlsObservability

Every meaningful delegation decision draws on all three at once.

This is why ACE is neither a technical control framework nor a policy exercise. Managing delegated authority well requires all three capabilities working together.

What ACE gives an organizationFour aspects of one capability, not four steps.

Clear Boundaries

A consistent way to define what agents may do, where they may act, and when human judgment is required.

Shared Decisions

A common language so business, legal, security, risk, technology, and operations can make authority decisions together.

Enforceable Control

A way to translate leadership choices into workflows and technical controls that operate while agents act.

Organizational Learning

Decisions, exceptions, near misses, and outcomes create evidence the organization can use to refine authority and controls over time.

The Enforcement Envelope

Define the Boundaries Before the Agent Acts

Every AI agent operates within some set of boundaries, whether the organization designed them deliberately or allowed them to emerge through permissions, tools, workflows, and technical defaults.

ACE calls the deliberately defined boundary around delegated authority the Enforcement Envelope. It establishes the conditions under which an agent can act on the organization's behalf and where greater oversight or human judgment is required.

That boundary has to account for more than access. An agent rewarded for completing a task will find paths its designers never considered, which means a boundary that exists on paper can still be exceeded in practice.

The goal is not to eliminate autonomy. It is to make autonomy intentional.

Customer dataPerson decidesReached anyway
Internal toolsPerson decidesReached anyway
PaymentsPerson decidesReached anyway
ApprovalsPerson decidesReached anyway
Agent
Conditions
Routine operations
01What can it do on our behalf?
02Where does its authority end?
03When should a person decide?
04What is it optimizing for?

A boundary matters only if it can hold when the agent is actually working.

The Insider You Built shows you how

Better Control Can Enable Greater Autonomy

Good governance should do more than prevent failure. By making delegated authority clearer and more enforceable, organizations can make better decisions about where AI can act independently, where human judgment adds value, and where greater autonomy can support better performance.

01

Scale AI With Confidence

Expand agent authority without relying on blanket restrictions or unmanaged trust.

02

Accelerate Adoption

Give leaders and teams a clearer basis for approving higher-value use cases.

03

Increase Delegated Value

Make more valuable work eligible for AI while reducing unnecessary friction and costly failures.

04

Strengthen Reliability

Reduce the chance that legitimate authority produces outcomes the organization never intended.

05

Improve Accountability

Make ownership of authority, exceptions, and outcomes clear across human-agent workflows.

06

Preserve Adaptability

Adjust authority and controls as technology, threats, business needs, and regulations change.

The larger shift

Work Is Changing Hands

The challenge is not simply to deploy AI safely. It is to build an organization that can govern work as authority moves among people, agents, tools, and systems.

ACE embeds control into how authority is delegated, exercised, observed, constrained, and refined, helping organizations become more capable and resilient as AI becomes part of how work gets done.

How ACE was built

Built for the Way Organizations Actually Work

ACE grew out of years of work across government and industry helping organizations adopt emerging technologies, build governance and security programs, and turn policy into practice.

ACE brings together lessons and perspectives spanning
GovernanceSecurityPolicyRisk managementPeople & cultureOrganizational designChange managementTechnologyGeopolitics

The goal is not simply to manage AI risk, but to create the conditions for technology to work in our favor.

These ideas continue to be informed and refined through the work of CAS Strategies with organizations navigating AI adoption, governance, and security.

Book cover The Insider You Built: Accountability and Governance of Autonomous AI Agents, by Camille Stewart Gloster

What the Book Teaches You

This page introduces the core idea. The book shows you how to put it to work.

ACE provides a practical approach to identifying delegated authority, deciding where human judgment belongs, defining enforceable boundaries, organizing accountability across functions, and adjusting controls as your organization learns.

Order the book
In the book you will learn how to

Understand how delegated authority changes organizational risk and accountability

Coordinate governance across organizational, operational, and technical functions

Translate leadership intent into operational practices and technical controls

Govern agents as they act, adapt, and interact

Bonus chapter

ACE Applies to Your Own Life Too

The same delegation questions arise as AI begins communicating, scheduling, purchasing, recommending, and taking other actions on your behalf. What have you authorized it to do, under what conditions, and where do you want to keep deciding for yourself? The book includes a bonus chapter applying delegated authority and retained human judgment to everyday AI use.

Included with every book purchase.
Get the complete framework

The Insider You Built

Accountability and Governance of Autonomous AI Agents, by Camille Stewart Gloster.

Order the book