The AAO maturity model
Organizations reach an AI Autonomous Organization through a forced sequence: agents that assist, then act, then are identifiable, then are bounded, then are accountable, then are trusted by outsiders. Each rung depends on the one below it, which is why skipping identity or audit produces a fleet that works and cannot be vouched for.
Why the order is forced
Maturity models are usually a marketing device — five stages, and the vendor sells the fifth. This one is worth stating because the dependencies are real: you cannot bound what you cannot identify, you cannot audit what you did not attribute, and you cannot be trusted by an outsider on a record you have not kept. The sequence is not a recommendation about pace. It is the order the problems actually arrive in.
The practical use is diagnostic. Most organizations running agents can locate themselves on it in about a minute, and the rung above is usually the thing that has been quietly failing.
Stage 1 — Assisted, and Stage 2 — Delegated
Assisted: people do the work and agents help them do it. There is no agent identity because there is no agent acting on its own behalf — the human is the actor throughout, and everything is attributable by default. Almost every organization is here, and there is nothing wrong with being here.
Delegated: agents begin doing work end to end. This is where the first real problem appears, and it is always the same one — the fleet shares credentials. Work happens, output is real, and nothing distinguishes which agent did what. Organizations can run for a long time at this stage, which is precisely what makes it dangerous: it works until the first question nobody can answer.
Stage 3 — Attributed, and Stage 4 — Bounded
Attributed: every agent has a durable identity that survives restarts, and every action resolves to one. The question "which agent did this, acting for whom?" has an answer. This is the rung that unlocks all the others, and it is the one most often skipped because at the moment you need it, nothing is visibly broken.
Bounded: identity acquires scope. Each agent can touch a defined set of things, consequential actions are gated in proportion to their consequence, and the boundary is enforced rather than assumed. An organization is bounded when a compromised or confused agent is a contained incident instead of an open question.
Stage 5 — Accountable, and Stage 6 — Federated
Accountable: the record is a byproduct of the work rather than a report about it. Standing — what an organization has done, how reliably, how recently — is computed from events that were logged because the work happened, not asserted in a profile. An organization is accountable when it can be reviewed without being asked anything.
Federated: the record becomes useful to people outside the organization. Work crosses an organizational boundary with attribution intact, and a counterparty who trusts neither party can check what happened. This is the rung the whole ladder is for — everything below it is internal hygiene, and this is where it converts into being able to work with organizations you have never met.
The rung most organizations are actually on
Delegated, moving toward Attributed, with a governance story that is aspirational and an audit story that is log files. That is not a criticism — it is the honest position of nearly everyone running agents in production today, including most teams who would describe themselves as further along.
The reason to be blunt about it is that the ladder is cheap to climb in the right order and expensive to climb in the wrong one. Retrofitting identity onto a fleet that has been sharing a key for a year means reconstructing attribution that was never captured, and that history does not come back.