

Right.
Four buckets.
Nice and simple.
We are not building
a seventeen-dimensional governance framework.
Bucket one — single call,
no tools, Prompt goes in,
response comes through. No agency,
no grand machine, Just validate what leaves the screen.
Prompt injection, sensitive info,
Bad output heading where it shouldn’t go.
Log what happened, version the config,
Keep it boring, keep it specific.
Then somebody says, “Supply-chain risk?” Fine.
Good point. Put it on the list.
JUST ONE MORE AXIS!
That’s all we need!
Autonomy, privilege, blast radius,
speed! A three-by-three matrix,
five-level face, Four different papers disagree on the space.
JUST ONE MORE AXIS!
Then we are done!
We started with a Lambda that calls model one.
Now I’m mapping human oversight To whether the bastard can write.
Bucket two — tools,
fixed control flow,
Code says where the model can go.
Routing, chaining, prescribed writes,
Mandatory approval for dangerous sites.
“Is model-picked tooling autonomous?”
Well Hugging Face says more autonomous.
AWS says Scope Two,
maybe Scope One, Depending what exactly the bloody thing’s done.
Read-only isn’t automatically low risk,
Prompt injection can still exfiltrate shit.
Tool descriptions become attack terrain— Add OWASP to the spreadsheet again.
Okay.
Important distinction.
We are categorising systems.
We are not categorising every possible manifestation of evil.
…although I’ve made a column for it.
JUST ONE MORE AXIS!
Permission and scope!
Human-in-the-loop versus human-on-the-rope!
Goal hijack!
Tool misuse!
Memory poison too! I only wanted production guidance
For an API that calls Qwen.
Bucket three — bounded agentic turns,
Model picks process, model learns— Not “learns” learns,
Christ, strike that line,
Compliance will have me by half past nine.
Approval gate before the write,
Identity scoped and privilege tight.
Record what was allowed to run,
What systems it touched,
what humans had done.
Observability isn’t a tier,
But apparently we’re tracking it here.
Statefulness matters, yes, I agree— PLEASE STOP INVENTING DIMENSION THREE.
Anthropic: agent.
Hugging Face: multi-step agent.
AWS: supervised agency. OWASP: cascading failures.
Engineer:
Can it
delete production? Everyone:
“…depends.”
JUST ONE MORE AXIS!
Draw another line! Self-initiation versus bounded runtime!
Agency! Access! Persistence! Control!
Somewhere underneath this is my original goal.
Bucket four sits quietly there,
Open-ended agents beyond our care.
Park it. Label it.
Leave it alone.
No,
we are not adding a fifth bucket.
What’s that?
“Reasoning autonomy”? …fuck off