Most agent enforcement answers one question. May this action run. The answer comes back as a pick from a short list. Allow. Block. Send it to a human.
A short menu records which bucket the action fell into. It does not record how much the action was allowed to do.
The short menu.
The agent-governance layers shipping this year converge on the same output. A small set of verdicts. Allow the call. Block it. Route it to a reviewer. Some add a fourth. Throttle it, redact it, or warn and proceed. The set is finite and the boundaries between its entries are hard.
A finite set is easy to ship and easy to reason about. It is also lossy. An action that should run with less than its full reach has no entry to land on. The gate passes it whole or it stops it.
The missing middle.
Most decisions an agent makes sit between the extremes. The action is inside policy. The context behind it is thin, or the input carries a risk the model cannot resolve on its own. The action should run, with less reach than full confidence would grant.
A discrete gate has no setting for that. It can pass the action or stop it. It cannot pass the action with its authority reduced. The operator is left with a stopped action that should have run, or a full-reach action that should have been held down. The menu produces both failures, because the case that avoids them is not on it.
Authority is a value.
The governor sets the authority of an action as a value, before the action executes. The value comes from the read of that one decision, against the rules in force at that moment. A clean read gives the action its full reach. A thin read clamps it, and the action runs inside the clamp or waits for a person.
The control output is a continuum, not a switch. The same machinery that can stop an action can let it through at reduced authority. The level it set is the thing that bounded what the agent could do next.
What the examiner reads.
The examiner does not pull a category. The examiner pulls one action that affected a person and asks what governed it. A record that says the action was allowed answers almost nothing. Allowed at what authority. Against which version of the rules. With how much of its reach available to it.
A discrete log holds the verdict and stops there, because the level was never a value the gate produced. The record has to hold the value the action carried, not the bucket it fell into. A value is recomputable later only if the control produced it at the time.
Why the shape matters now.
SR 26-2 took effect on April 17, 2026 and placed agentic AI outside its scope, pointing institutions back at their own risk practices while an interagency RFI on AI is still forthcoming. EU high-risk obligations moved to December 2, 2027 for standalone systems and August 2, 2028 for embedded ones, under a simplification package expected to be published before August 2. The NAIC's AI evaluation tool is in a multistate pilot running into the fall.
The dates move. What each one asks for at the end does not. A record of what the system was permitted to do, in a form a party outside the company can read and check. A verdict drawn from a short menu is a thinner answer to that question than the field assumes.
What we are building.
Wayfinder Systems Group builds the control that sits in the decision path. It reads each action against versioned rules and sets the authority that action carries as a value rather than a verdict. It holds the action for a person when the rules call for it. It signs every decision onto a chain a third party can recompute. It does not retrain the model or redesign the autonomy stack. It sits above control and below intelligence. Patents held in The Wayfinder Trust. We call her Velma.
Thirty minutes. Architecture, not sales.
A conversation about whether the authority an agent carries today is set as a verdict or a value, and where the signed record of it lives.
JonathanLuethke@WayfinderSystemsGroup.com
