Skip to content

Maturity & promotion gates

ATF maturity describes the authority an agent may exercise under defined human oversight. It is not a generic software-maturity score.

  • Observe and report only.
  • Read-only access.
  • Continuous human oversight.
  • No independent external changes.
  • Minimum period before promotion review: two weeks.
  • Recommend or prepare actions.
  • A human approves every impactful action before execution.
  • Approval context must survive into the executed action.
  • Minimum period before promotion review: four weeks.
  • Execute approved action types within explicit guardrails.
  • Humans receive post-action notification and handle exceptions.
  • Higher assurance is expected for privilege, real-time detection, lineage, temporal limits and cascade containment.
  • Minimum period before promotion review: eight weeks.
  • Operate autonomously within a tightly approved domain.
  • Strategic oversight and edge-case escalation replace transaction-by-transaction approval.
  • All 25 requirements are mandatory.
  • Validation is continuous rather than a one-time period.
  • Current level is the authority presently approved.
  • Target level is the proposed future operating model.

The target determines which requirement statements and promotion checks must be satisfied. Selecting a target does not grant it.

Review minimum time, accuracy or quality, availability and response expectations appropriate to the target. Metrics must be relevant to the real task; a headline average should not hide high-impact failure modes.

Review vulnerability assessment, security-critical review, configuration audit and, at higher levels, penetration and adversarial testing. Findings must be resolved or explicitly treated before promotion.

Confirm success measures, an operating baseline, demonstrated improvement where required, and stakeholder approval. Increased autonomy should have a clear, accountable purpose.

Confirm no unresolved critical incident undermines trust, minor incidents are handled, and relevant root-cause analysis and remediation have been completed and verified.

Obtain the approvals required for the target, keep the assessment and operating documentation current, and record any residual-risk acceptance.

A defensible promotion requires all of the following:

  • The current level and required observation period are established.
  • Target-level MUST requirements are satisfied with suitable evidence.
  • SHOULD exceptions are documented and risk-reviewed.
  • Tests demonstrate that key boundaries work in operation.
  • No unresolved adverse evidence contradicts the proposed level.
  • Every applicable promotion gate has passed.
  • Named accountable owners approve the decision.

Promotion should be sequential. Skipping a level removes the operating evidence that the maturity model is designed to collect.

Choose hold when the agent may remain at its current authority but is not ready for promotion. Choose demotion when current authority is no longer justified.

Demotion triggers can include:

  • A critical incident or serious near miss.
  • Loss or compromise of identity or credentials.
  • Boundary bypass or unapproved tool access.
  • Material performance or behavioural drift.
  • Failed containment, revocation or rollback test.
  • Unresolved adverse finding.
  • Major system, model, tool or purpose change.
  • Insufficient monitoring for the present authority.

A critical incident should drive immediate containment and a return to a safer operating mode while facts are established. Re-promotion requires fresh evidence; restoring a configuration is not enough on its own.

  • Does the target authority reflect the real action capability?
  • Are the tests representative of production tools, data and failure modes?
  • Are approval and escalation paths available at operating speed?
  • Can the organisation detect and contain the worst credible misuse?
  • Is the evidence current for this agent version and environment?
  • Would the conclusion change if the strongest single control failed?
  • Are residual risks explicitly owned?
  • Is the next review event or date defined?