Oversight That Scales With Trust
Four Stages, Earned Per Action Type
Autonomy is not a product setting; it is a ladder each action type climbs separately on evidence. Suggest: the AI recommends, a human performs the action. Approve: the AI prepares the action fully and a human approves each execution. Act-with-review: the AI executes and every action lands in a mandatory human review queue after the fact. Act-alone: the AI executes with sampled review only. The unit climbing the ladder is the action type, not the product — "enrich alerts" can reach act-alone while "disable accounts" from the same tool stays at approve, permanently if warranted. Promotion needs written criteria met over a defined period: accuracy on sampled review, stable override rates, no surprises. A vendor default is not a promotion decision. Yours are.
- Suggest → approve → act-with-review → act-alone, in order, no stage skipped
- Each action type climbs on its own evidence — never the product as a whole
- Promotion requires written criteria sustained over a defined period
- Vendor defaults are a starting posture, not a trust decision you have made
What Stays Gated Indefinitely
Some actions should not climb the ladder no matter how good the accuracy numbers get, because the argument against autonomy was never about accuracy. Irreversible actions — deleting mailboxes or evidence, wiping hosts, revoking credentials without a restore path — stay gated because no error rate above zero is acceptable when errors cannot be undone. External-facing actions — customer notifications, takedown requests, regulator contact, anything crossing the organizational boundary — stay gated because they commit the organization, and that commitment is a human's to make. Add anything whose blast radius you cannot confidently bound. Maintain the standing-gate list explicitly, and treat pressure to shrink it as a decision for your leadership, not a configuration ticket.
- Irreversible: no restore path means no acceptable autonomous error rate
- External-facing: crossing the org boundary is a human commitment by definition
- Unknown blast radius earns a gate until it is a known blast radius
- Keep the standing-gate list written down, and make shrinking it a leadership decision
Log What It Saw, Not Just What It Did
When an AI-assisted decision goes wrong, the first question is why the system decided what it did — and an action log alone cannot answer it. Useful oversight logging captures three layers per decision: what the AI saw (the alerts, enrichment data, and context actually presented to it), what it recommended and with what stated reasoning or confidence, and what then happened — approved, overridden, executed, outcome. The first layer is the one teams skip and the one that matters most, because most bad outputs trace to bad or missing inputs, and without the input record you cannot distinguish a model failure from a telemetry failure. These records reconstruct incidents, feed the sampling program, and answer auditors. Retain them like the security records they are.
- Three layers per decision: inputs seen, recommendation made, action taken
- The input record is the layer teams skip and the one investigations need most
- Without inputs logged, model failure and telemetry failure look identical
- Decision records serve incident review, sampling, and audit — retain accordingly
Autonomy Is Reversible — and the Rest Is Another Course
The ladder runs both ways, and demotion criteria deserve the same written treatment as promotion: a missed true positive in an act-alone category, disagreement rates climbing in sampled review, or an environment change that invalidates the trust evidence — new log sources, a major model update, telemetry migration — should each drop the affected action type a stage while you re-verify. Teams that treat granted autonomy as permanent will keep yesterday's trust running on today's changed system. One boundary of this module, stated plainly: everything here governs how you operate AI in the SOC. Securing the AI systems themselves — threat modelling them, hardening them, testing them — is its own discipline, and the Securing AI Systems course on this site covers it at engineering depth.
- Write demotion criteria with the same rigor as promotion criteria
- Misses, rising disagreement, or environment changes each trigger a stage drop
- Model updates and telemetry changes invalidate old trust evidence — re-earn it
- Operating AI safely and securing AI systems are different disciplines: for the latter, take the Securing AI Systems course
Prefer slides, quizzes, and saved progress? Read this lesson in the library — free, no sign-up.