← All articles

September 7, 2026

What Counts as One Action

A governor sets how much authority the next action carries. Something upstream decided what one action is, and every bound in the envelope is written in that unit whether or not anyone stated it.

By Jonathan Luethke

A governor sets how much authority the next action carries, per action, at runtime. Before it can do that, something has to decide what one action is. That decision is made upstream of the governor, before the run, usually by whoever wrote the integration, and it is almost never written down.

The governor is exact on whatever it is handed.

A governor receives a proposed action and returns a grant. The boundary of that action arrives already drawn. One tool call. One transaction. One containment step against one host across one window. One maneuver segment.

Nothing in the governor establishes that boundary. It reads the declared envelope, assesses divergence, sets the grant, and enforces it on the object presented to it. The arithmetic is exact on that object. The governor has no way to know it was handed the wrong one.

A bound is a number and a unit, and the envelope states the number. The unit comes from the integration. Two builds can load the same envelope file, enforce it correctly, and govern two different systems, because a bound of thirty per minute means one thing when an action is a containment step and another when an action is an inspected event.

Reach and rate answer different questions.

Envelope bounds fall into families. Reach asks how far one action extends: how many targets, hosts, tenants, accounts, or rows fall inside its effect. Rate asks how many actions occur per interval. Magnitude asks how much each one moves.

These are not interchangeable, and the same measured quantity fed into the wrong family produces a bound that is enforced correctly and means nothing correct. A reach bound does not limit how many events a single action covers. It limits how far that action reaches. An action that quarantines one host covers every event on that host, and the reach bound was satisfied once.

The failure is quiet because both readings are arithmetically clean. Map one governed action onto each arriving event and a rate bound will refuse nearly all of them, on a stream whose arrival rate is a property of the sensor rather than of the risk. Map one governed action onto each target across a window and the same envelope, unchanged, admits the work, because the number of things to act on was the number of targets and not the number of observations about them.

A false ceiling arrives dressed as a finding.

When the unit is wrong, the shortfall does not present as a bug. It presents as a discovered property of the domain. The report says the envelope permitted a small fraction of the work to be automated and the rest went to a person, and that sentence reads like governance doing its job under a hard constraint.

There is a tell. A real ceiling scales with something about the risk: the consequence of the action, the confidence available at decision time, the reach of the effect. A manufactured one scales with the arrival rate of the input. If ingesting the same telemetry at twice the sampling frequency halves the automated share while nothing about the hazard changed, the ceiling is describing the instrument.

The cost of not catching it is that the number gets published. An automation limit stated in a governance report becomes a planning input, and staffing gets sized against a bound that was never about the world.

The remainder has a rate too.

What gets handed to a person is not governed by the governor. Routing an action to a review queue is a grant of zero authority attached to a claim that something else will decide. The claim is often true. It is also a claim about a channel with a throughput, and that throughput is finite in a way the governor's is not.

Two outcomes follow when the arrival rate exceeds the channel. The remainder waits, and the delay is itself consequential, since a containment step deferred four hours is a different action from the same step taken now. Or the remainder flows through on approval at the rate it arrives, which satisfies every count in the report and changes nothing about the outcome.

Coverage belongs on the constraint side of the design rather than the output side. When every arriving event falls inside exactly one governed action, coverage is total by construction and there is no remainder to route anywhere. A run that cannot cover its input should refuse to finish rather than emit a partial result with a leftover attached to it.

The unit belongs in the declaration.

The unit of the grant should be the unit of the effect. The smallest thing that produces a durable consequence the envelope cares about is the thing to put a grant on. Below that boundary the governor is spending decisions on events that change nothing. Above it, a single grant is covering an effect the envelope wanted bounded separately.

That makes the unit a declared object, not an implementation detail. For each class of action the envelope should carry what one action is, what it reaches, and how long it runs. Duration is the companion problem, since a governor reads at one instant and the action lands later, and the horizon of its forward look has to cover the interval the action occupies. Boundary and duration are two facts about the same object, and both come from the plant and the integration rather than from the model.

The governor's sharpest behavior depends on getting this right. It can grant less authority on an action whose present trust reads higher, because its forward look caught a divergence coming before the outcome landed. That forecast is made about a specific action over a specific span. Draw the boundary wrong and the forward look is anticipating the wrong thing accurately.

The obligation is written per decision.

Colorado enacted SB 26-189 on May 14, 2026, replacing the 2024 Colorado AI Act, effective January 1, 2027. It requires meaningful human review for consequential decisions made by covered automated decision-making technology, and defines it demandingly: a reviewer with authority to override, trained for the role, who does not default to the system's output. EU AI Act Article 14 places the human oversight duty on the deploying party, with high-risk obligations falling on December 2, 2027 for standalone systems and August 2, 2028 for AI embedded as a safety component.

Both instruments name a path for a decision. Neither states how many decisions per hour that path has to absorb, because an obligation written per decision does not carry a rate. The rate is supplied by the deployment, and it is supplied by the unit the integration chose.

SR 26-2 took effect on April 17, 2026 and placed generative and agentic AI outside its scope, with the interagency request for information still pending nearly five months later. The NAIC AI Systems Evaluation Tool pilot closes this month across twelve states, with re-exposure through September and October and adoption sought at the Fall National Meeting in November 2026. An evaluation tool asks what a governance framework covers. The prior question is what one covered thing was.

What we are building.

Wayfinder Systems Group builds a runtime governor. It sits above control and below intelligence, sets how much authority each action carries against an envelope declared before the run and outside it, and enforces that grant in front of the actuator rather than beside the log. It does not retrain models or redesign an autonomy stack. It bounds what the stack is allowed to do while it is doing it, and signs what it granted. We call her Velma.

Next step

Thirty minutes. Architecture, not sales.

A conversation about where the action boundary sits in your deployment, what your envelope bounds are actually written in, and whether the automation ceiling in your governance report is describing your risk or your sampling rate.

JonathanLuethke@WayfinderSystemsGroup.com