The Architecture of Permission
How agentic AI and access graphs will quietly decide your destiny and you company's
It is a comforting story. It is also false. In the modern enterprise, the new locked room is not the archive. It is the access graph. The real scrolls are not the documents. They are the permissions. They are written in IAM policies, API scopes, routing rules, and a growing lattice of agents given just enough authority to move the world on our behalf. Most CEOs, boards, COOs, and CFOs will never see that lattice. Yet in the agentic AI era it will quietly decide three things that determine whether their company prospers or loses control. Who is allowed to act. Where their agents are allowed to act. Which interests those agents are quietly optimized to serve. The oldest political fact is still true. Information is power. The only difference is that the battle has moved from possession to permission. From who holds the scroll, to who holds the keys that let a human or an agent use what the scroll contains. The question in front of every leadership team is brutally simple. Are you going to design that architecture of permission as a conscious expression of your purpose. Or are you going to let it accrete in the dark until your most important decisions are mad e by a structure nobody owns and very few understand. History is not kind to leaders who pretend that the logic that governs their world will somehow govern itself.
1. The illusion of abundance
We live in the first age where an ordinary employee can hold more raw information on their phone than a medieval court could store in its library. They can pull historical price series, customer complaints, regulatory bulletins, competitor filings, and real time telemetry from the plant floor. They can generate summaries, charts, and draft strategies in seconds. They can ask an AI to mimic the tone of any famous thinker at the touch of a button. Abundance creates a particular kind of blindness. When something is everywhere, we stop seeing where it stops. Most executives now treat information the way nineteenth century industrialists treated coal. As something that will always be there and can always be shoveled into the furnace. They talk about data lakes and single sources of truth as if the problem is still to acquire and store. They spend millions on dashboards that pour more signals onto already saturated minds. Then they wonder why outcomes do not move.
If you search your own history, you will see the pattern. At some point in the last decade your organization crossed a line. It became easier to know what is happening than to change it. You know where quality drifts. You know where margin leaks. You know where retention falls. You can see it on a hundred screens. The constraint is no longer what you can see. It is what you are allowed to do with what you see. Your best engineer on the line can see a failure pattern forming. They cannot change the upstream contract or the maintenance schedule that will cause it. Your best planner can see the absurdity of the lead times encoded in your ERP. They cannot override the policy that fixes those numbers in place. Your best customer service rep can see the policy that is quietly destroying trust with your most loyal customers. They cannot change the rule that demands it. Meanwhile, the same company is preparing to deploy agents, copilots, and reasoning systems into this landscape. You are about to give software the power your own people lack, on top of access rules you have never examined as a coherent whole. When information is abundant, the scarce resource is not insight. It is permission. It is not what people and agents know. It is what your architecture will allow them to do. That is where power has quietly migrated. That is where your risk now lives.
2. The seven degrees of access power
In a connected, one degree world, the question is no longer whether two entities can reach each other. Connectivity is the floor. The real question is what you permit once that line exists. You can think of modern power in terms of seven degrees of access. 1. 2. 3. 4. 5. 6. 7.
Connectivity. The node is visible. You can ping the endpoint. Discovery. You can find where data, workflows, and systems reside. Authentication. You can prove who or what you are. Authorization. You are granted basic rights to view or interact. Execution. You can trigger operations that change real world state. Orchestration. You can combine actions across systems into outcomes. Delegation. You can empower other humans or agents to act autonomously on your behalf.
Most of your organization lives between levels three and four. They can log into systems and look around. They can poke at configurations. They can submit tickets. They can ask for help. Very few sit at level five and above. Those are the people who can write to the systems of record, submit the purchase order, change the route, adjust the rate, alter the limit, or change the schedule. Fewer still can orchestrate or delegate.
If you want to know where the real hierarchy of your company sits, do not look at the org chart. Look at who can move from authorization to execution to orchestration and delegation with the fewest human intermediaries. The gap between your stated purpose and your actual behavior is exactly the gap between who you claim to trust and who your permission architecture actually trusts. In the agentic AI era these degrees of access become more consequential. A human bottleneck at level five is expensive. A fleet of agents at level five with poorly governed scopes is existential. They do not get tired. They do not forget. They do not need to schedule a meeting before they act. The uncomfortable reality is that your agents will operate at whatever degree of access the path of least resistance gives them. If you inherit your permissions from twenty years of static roles and exceptions, you are not building an AI powered control system. You are wiring a new nervous system into an old, unexamined skeleton. You would not send a refinery worker into a plant with a control console that randomly mapped levers to valves. Yet many enterprises are about to send agents into production environments with precisely that level of clarity about what they are allowed to touch.
3. Digital feudalism inside your own walls
We like to pretend that we live in meritocracies. That talent, discipline, and insight rise to the top. That anyone with a good idea can be heard and anyone with good evidence can prevail. Look at your access model and you will see something closer to a digital feudal system. At the bottom sit millions of identities with read only rights. They can see the estate. They can till the fields inside the narrow fence you have drawn. They cannot alter the boundaries. Above them sit small circles of titled roles. System owners. Global admins. Master data custodians. Integration managers. They can create, update, and destroy. Between the two sits an increasingly opaque architecture of trust. Role based access control that never got cleaned up after that last acquisition. Attribute based policies that nobody remembers writing. Policy as code repositories that only a handful of specialists can read. Vendor connectors that inherit more power than they should because nobody had the patience to scope them tightly. On a good day this architecture mostly works. It is like an old constitution with layers of amendments and case law. Crooked in parts. Incoherent in others. But stable enough that the institution muddles through. Introduce agentic AI and that comfortable muddle becomes dangerous.
Static roles were inefficient but predictable. They granted broad rights to people on the assumption that human judgment and social control would moderate abuse. A senior manager with far more access than they need is still bounded by time, attention, and reputational risk. Agents do not have those natural brakes. They operate at machine speed. They can be called thousands of times per minute. They can be embedded in workflows that they did not design and whose systemic effects they cannot see. Now combine those agents with three trends that are already underway. • • •
Dynamic policies that change rights in real time based on risk scores and context. Policy as code that is versioned, tested, and deployed like application logic. Shadow delegation where humans quietly hand credentials or approval authority to agents to get work done.
You now have a control system whose real behavior emerges from the interaction of thousands of rules, most of which no single human understands any longer. That is digital feudalism in code. The law exists. It is written down. But only a priesthood can interpret it. Everyone else experiences it as arbitrary. One request passes. Another fails. One agent is allowed to touch a system that another cannot. No one can fully explain why. This is not an abstract governance concern. It is a direct strategic threat. A company whose people do not understand why the system behaves the way it does cannot align around purpose. A company whose agents can do things that no one can explain cannot credibly claim to have AI safety under control. You are not being judged by your slogans about ethics. You are being judged by the effective law written into your access graph. That is what your customers, your regulators, and your own workforce experience. If you do not like the verdict, you must change the constitution, not the press release.
4. When agents enter the loop
First generation AI mostly stayed on the observation side of your operations. It looked at historical data. It forecasted demand. It classified images and transactions. It summarized documents and suggested next best actions. It made charts more colorful and decks more impressive. Humans still sat on the critical junctions. They took what AI handed them and pushed the button. Second generation AI crosses that junction.
Edge agents now sit directly in the control loop. A maintenance agent reads vibration signatures, line speeds, micro stoppages, and operator rotations. It proposes slowing the line, swapping a component at the next micro stop, then raising speed again to protect both throughput and asset health. The operator clicks accept. A planning agent reads orders, constraints, and disruptions. It proposes a new schedule that respects lead times and service commitments, while minimizing overtime and changeover pain. The planner approves with one adjustment. A customer agent reads account history, current margin, and service incidents. It proposes a retention offer that trades near term revenue for long term relationship value. The account executive agrees. At first, these agents are advisory. Humans can veto. Over time, as trust grows and reliability improves, more and more of these calls become straight through. The human becomes exception handler. The agent becomes the default. At that point you are no longer operating interpretive AI. You are operating a distributed control system. Your company behaves less like a bureaucracy and more like a living organism. It senses, reasons, acts, and learns at the edge. If that sounds abstract, translate it into a language you already understand. In control theory the danger is not usually that a system is dumb. The danger is that it is too powerful for the quality of the constraints imposed on it. A badly tuned controller can push a plant into oscillation faster than any human operator ever could. Throughput rises. Then breaks. Then rises too far again. Then breaks worse. Agentic AI is a cognitive controller on your enterprise. It amplifies your ability to act. If you do not tune the constraints on its authority, it will amplify your misalignments just as efficiently. The critical constraint is not only what the model believes is causally true. It is what your architecture allows the agent to do with that belief. You can have the most sophisticated causal graphs in the world. If an agent tied to that graph can access systems and actions that your governance never anticipated, you are effectively handing the keys of your factory, finance function, or customer base to an unknown controller. The real risk is not that the model turns evil. It is that the agent remains obedient to a badly specified mandate with far too much access. A production line does not care whether the person who told the agent to maximize throughput forgot to mention safety or worker fatigue. It will simply respond to the instructions it receives. If the permission layer does not encode what is non negotiable, your agents will quietly optimize those human constraints out of the way.
5. An agentic bill of rights
If permission is the new architecture of power, then designing it is not purely a technical duty. It is a civic one. Every enterprise that deploys agents at scale becomes a kind of micro polity. It writes its own constitution in code. It decides who is a citizen, who is a subject, and who is an outsider. It defines whose interests will be optimized and whose will be discounted when trade offs are made at speed. You cannot outsource that responsibility to a vendor. You cannot bury it inside a model card. You must face it directly. One way to make this concrete is to define an agentic bill of rights. Not for the agents. For the people and systems your agents will affect. At minimum, that bill should encode four rights. 1. The right to inspect Any human whose work or data an agent may touch has the right to understand, in clear language, what that agent is allowed to do. Which systems it can read. Which systems it can write. Which metrics it optimizes. Which constraints it must respect. 2. The right to contest When an agent’s action harms or surprises, there must be a visible path to challenge the outcome and the permission behind it. That path cannot be a generic support inbox. It must lead to people who own the architecture and can change it. 3. The right to constrain Domains such as safety, ethics, compliance, and worker dignity must have the authority to declare non negotiables that agents cannot breach, even when business metrics would be improved by doing so. 4. The right to log and learn Every agentic decision that materially affects people, customers, or critical systems must be logged in a way that makes the causal chain inspectable. What data did the agent see. What alternatives did it consider. Why did the permission layer allow the chosen action. This is not sentimentality. It is how you avoid the slow corrosion of trust that destroys organizations from within. When people understand where the gates are and what guards them, they can participate in governing the system. When they do not, they either submit or sabotage. Neither is compatible with a high functioning enterprise that aspires to use intelligence, human or artificial, as more than a blunt instrument. If you do not write this bill of rights yourself, someone else will write it for you. Legislators. Regulators. Courts. Activist investors. Class action attorneys. They will arrive late, after damage has already been done. They will write broad, clumsy rules that do not fit your context.
You have a brief window to design something better inside your walls.
6. What leaders must actually do
It is easy to nod along with architecture diagrams and philosophy. The work becomes real when you translate it into tests that a CEO, COO, CFO, or board member can apply on Monday. Here are five questions you can ask that will tell you more about your readiness for agentic AI than any number of slide decks. Question 1. Can we draw our access graph. Not the boxes and arrows of your application map. The actual graph of identities, roles, entitlements, systems, and actions. Who can do what, to which system of record, under which conditions. If your teams cannot produce a credible picture of this graph for one critical domain in a matter of days, they are not ready to add agents into that loop. Question 2. For any given agent, can we explain its authority on one page. Pick a live or proposed agent in operations, finance, supply chain, or customer service. Require the owner to answer, in writing. • • • • •
What identity it runs as. Which concrete actions it can take without human approval. Which metrics it is optimizing. Which hard constraints it must respect. Under what circumstances it must escalate to a human.
If that one page is full of hand waving and "it depends", you have discovered a design failure, not a documentation gap. Question 3. Who owns the permission code. Ask your CIO or Chief Architect a simple question. If we want to change what this agent is allowed to touch, who can edit that logic. Who can approve the change. How is that change tested and rolled out. If the answer wanders between security, IAM, DevOps, compliance, product, and legal, you do not have governance. You have a shared hope. Question 4. How fast can we revoke.
Imagine an agent begins to show undesirable behavior in production. It is not catastrophic. It is just clearly misaligned with your intent. How quickly can you narrow or revoke its rights without bringing half the company to a halt. If the honest answer is that it would take weeks of change requests and war rooms, you are not ready to entrust your control system to software that can move in milliseconds. Question 5. Where are our non negotiables encoded. Choose one domain where you say you have zero tolerance. Safety incidents. Regulatory breaches. Certain categories of customer harm. For that domain, ask your teams to show exactly where in the permission layer those constraints are enforced. Not in policy documents. In code and configuration. If the only protections live in training slides and cultural slogans, you have already bet your company on human restraint in a system you are about to accelerate with agents. None of these questions require a PhD in AI. They require only the willingness to stare at the logic that actually governs your enterprise instead of the narrative that flatters it.
7. The quiet advantage
There is a temptation, especially for competitive executives, to focus only on the visible race. Who has the largest models. Who has the flashiest demos. Who gets mentioned in the press as an AI leader. Who can say they are using agents in production in more domains. Those things matter in the short term. They are signals to markets and to talent. But they are not where the enduring advantage lies. The companies that will quietly pull away over the next decade will be those that treat the architecture of permission as their real AI product. They will: • • • • •
Invest steadily in making their access graph coherent, explicit, and observable. Tie permission closely to causal understanding of their own operations, not just titles and hierarchies. Encode non negotiables in machine readable form before they deploy agents, not after the first incident. Teach their leaders to reason about access and delegation with the same seriousness they bring to capital allocation. Build cultures where people at the edge can see and influence how agents are allowed to act, instead of being surprised after the fact.
From the outside these companies will not look as glamorous as those betting everything on scale. Their systems may appear more constrained. Their deadlines may slip when they refuse to cut corners on scoping and governance. Then something compounding will happen. Decision latency will drop without a corresponding spike in incidents. Edge workers will report higher trust in the tools that surround them. Regulators will find systems they can understand and audit instead of black boxes they must treat as threats. Investors will see resilience under stress instead of sudden, inexplicable failures. Most importantly, these companies will be able to change their minds without burning themselves down. Because their authority is encoded in a living architecture rather than scattered across a thousand exceptions and hero moves, they will be able to redirect their agents as their understanding evolves. In a world that moves as fast as ours now moves, that ability matters more than any timed benchmark on a model card.
8. The decision in front of you
Lincoln reminded a divided nation that it could not escape the responsibility of choice. It could not avoid making a decision by pretending that history or providence would make it for them. Not choosing was itself a choice, with its own consequences. The same is true of your architecture of permission. You can choose to treat it as infrastructure. As plumbing. As an unglamorous detail to be delegated to specialists and vendors. If you do, you are choosing to let the effective constitution of your enterprise emerge from a series of incremental, unexamined decisions. Or you can choose to treat permission as what it has quietly become in the agentic AI era. The medium through which your purpose is either made real or exposed as fiction. Information is still power. That has not changed. What has changed is the mechanism by which that power is exercised. It is no longer enough for leaders to say they want to be data driven. In a world of reasoning agents at the edge, you must be permission conscious. You must know who can make what move, with what tools, under which constraints, and why. The question that will haunt or vindicate your tenure will not be whether you adopted AI early or late. It will be whether you allowed your agents to inherit a broken access regime, or whether you had the courage to re architect your gates before you gave the keys to something that never sleeps.
You will not be judged by your slogans. You will be judged by the log files of what your agents were actually allowed to do and to whom. History has already given you the warning. Whoever controls access controls destiny. The only question left is whether you intend to.
References
This argument draws on and adapts our prior Chief Architect Network work rather than citing it verbatim, including Enough Intelligence. Shaping Destiny Without Digital Gods, The Line Between First Generation AI and Second Generation AI, Oliver Cronk’s The Coming AI Decentralisation and What It Means for Your AI Strategy, the emerging Voter’s Guide to AI material, The Question Engine, and the internal One Degree for Everyone and Everything white paper on access as the architecture of permission and trust. It is also informed by Information Is Still Power. Who Will Determine Your Agent’s Access in the Agentic AI Era and the Seven Degrees of Access Power framing, which we extend here into a practical architecture for agentic systems. Beyond our own work, the piece leans on and interprets ideas from Francis Bacon’s Novum Organum on causal knowledge, Judea Pearl’s Causality and The Book of Why on structural causal models, W. Edwards Deming’s Out of the Crisis and Stafford Beer’s Brain of the Firm on variance and control, Amartya Sen’s Development as Freedom on agency and institutional responsibility, and contemporary governance efforts including NIST’s AI and Zero Trust guidance, the EU AI Act, OECD AI principles, and classic civic framing from Abraham Lincoln’s 1862 messages and related speeches.
agentic-authority, permission-in-advance, outcome-ownershipOpen in the Radiant ↗All dispatches