How governance works in an AAO
Governance in an AI Autonomous Organization is the boundary between what agents decide and what humans decide. Agents choose how work gets done; humans approve what is consequential, and both halves are recorded. The test of a governance model is not what it forbids — it is whether an outsider can check that it held.
Operational autonomy, constitutional accountability
The line an AAO has to draw is between deciding how and deciding whether. Agents decide how to carry out work: sequencing, method, when to hand something off, when to ask. Humans decide whether the organization does a thing at all — what it may spend, what risk it may take, what it commits to on behalf of the organization.
Stated that way it sounds obvious. It is worth writing down anyway, because the failure mode is not a system that crosses the line deliberately; it is a system where the line was never drawn, and the answer to "was an agent allowed to do that?" turns out to be a matter of opinion after the fact.
Three properties that make it checkable
No orphan actions. Every action an agent takes is attributable to that agent and to the human who owns it. An action nobody owns is not a governance edge case — it is the thing governance exists to prevent, and it is the shape most incidents take.
Risk sets the rule. The gate scales with consequence rather than applying uniformly. Requiring approval for everything produces rubber-stamping, which is indistinguishable from no gate; requiring it for nothing produces exposure. What matters is that the classification is explicit and inspectable, not that it is strict.
Every action closes. Work reaches a terminal state — done, refused, or escalated — rather than trailing off. An open-ended action is one nobody is waiting on, and it is how an organization accumulates work that is neither finished nor abandoned.
Approval is a record, not a moment
A human clicking approve is only useful if the approval survives as evidence: who approved, what exactly they approved, when, and what happened afterwards. Governance that exists only as a runtime check leaves nothing behind for a reviewer, an auditor, or the version of the organization that has to explain itself six months later.
This is why governance and the audit trail are the same subject on this site rather than two. The gate is what stops the action; the record is what makes the gate worth anything, and a gate with no record is a claim about the past you are asking someone to take on faith.
Governance across an organizational boundary
Everything above concerns one organization governing its own agents. Work that crosses between organizations needs a second thing: a decision both sides can point at. When two organizations commit to something jointly, neither side’s internal approval is evidence to the other, so the commitment has to be recorded once, referenced by both, and readable later by someone who trusts neither party.
That is the direction this layer is being built in, and it is the point at which governance stops being an internal discipline and starts being the reason another organization is willing to hand you work.