TRUST INFRASTRUCTURE FOR AGENTS

Stop trusting agents blindly.

Self watches what your agents actually do, joins it to human corrections and real business outcomes, and enforces how much autonomy each skill has earned.

SEE THE METHOD
PRIVATE PILOTS / 2026

WHY NOW

Agents got capable faster than anyone got ready to govern them.

CAPABILITY · OSWORLD TASK SUCCESS

12% 66% 2024 2026

The technical objection is gone. Agents now succeed on real computer tasks two out of three times, up from roughly one in ten just two years ago.

Stanford HAI, 2026 AI Index Report

DEPLOYMENT · ENTERPRISE APPS WITH AGENTS

<5% 40% 2025 2026 (FORECAST)

Agents are forecast to arrive inside the software you already run within the year, whether or not anyone signs off on governing them.

Gartner forecast, August 2025

THE GAP · GOVERNANCE FORECAST

40% BY 2027 WILL DEMOTE OR DECOMMISSION AN AGENT

Gartner's own diagnosis: enterprises treat governance as binary — locked down or fully trusted — and that is the root cause of failure.

Gartner, May 2026

THE STATE OF THE ART

Two ways to govern an agent. Both of them fail.

Enterprises running agents that move money, change records, or resolve exceptions almost always pick one of these. The third column is the whole product.

Review everything

Throughput capped

HUMAN REVIEW AGENT ACTIONS THROUGHPUT

A person checks every action. Volume stops at whatever the review team can absorb — and once the queue outruns them, approvals get faster, not better. The record still looks clean, because nobody is really reading it.

Evaluate once, trust forever

Blind after day one

HUMAN REVIEW MODEL v4.1 AGENT ACTIONS THROUGHPUT

One evaluation, then standing trust. Nothing in that assessment survives a model release, a changed tool, a rewritten prompt, or an input the agent never saw during testing — and nothing tells you when it stopped being true.

Self

Continuous · skill-specific · revocable

HUMAN REVIEW PROBATION AGENT ACTIONS THROUGHPUT

Oversight is set per skill, against evidence, and moves in both directions. A model release puts the affected skills back under full review until they re-earn what they had. Trust accrues slowly. It is revoked at the gate, immediately.

THE METHOD

Four streams, one ledger, one gate.

Self runs the same loop for every skill, and doesn't wait for it to run on its own. Every number on every screen is one click from the sessions that produced it.

01 · INPUTS

Agent telemetry

What the agent did — including scenarios Self injects itself, to see what it hasn't naturally encountered yet.

Human reviews and corrections

What a person approved, edited, escalated, or reversed.

Business outcomes

What turned out to be correct, costly, or harmful downstream.

Authority policy

How much autonomy your organization permits this skill to earn.

02 · BEHAVIORAL LEDGER

SKILLTOOLREVIEWSEVERITYOUTCOME
verify_invoice_vendorvendor_master.searchapprovedinformationalmatched
verify_invoice_vendorerp.invoice.geteditedminormatched
verify_invoice_vendorvendor_master.searchreversedmaterialpayment held
verify_invoice_vendorerp.vendor.matchapprovedinformationaloutcome pending

Append-only. Reference-only storage for sensitive payloads — Self keeps record identifiers, not your invoices.

03 · EVALUATION

  • Deterministic checks, applied the same way to synthetic and organic sessions alike
  • A human-written rubric where it takes judgment
  • Severity weighting — one critical failure outweighs a thousand routine successes
  • Correlated-failure clustering, so one bad upstream feed isn't averaged away
  • Drift detection across inputs, tool use, escalation, and calibration
  • Engagement-adjusted confidence, so rubber-stamped approvals count for less

04 · GATE

Maintain Current oversight holds. Nothing at the gate changes.
Promote Eligible for more autonomy — takes effect at the gate once accepted.
Probation A change or uncertainty tightens the gate until fresh evidence clears it.
Demote A failure or risk event locks the gate down immediately. No accept required.

AUTONOMY TIERS

Five tiers, all of them reachable.

Trust is calculated per skill, per agent version, per environment — never as one score for an agent. Select a tier to see what it means operationally and what Self has to see before it will let a skill operate there unattended.

TIER 3

Execute with exception routing

Posture
Bounded autonomy
Operating model
Routine actions proceed. Anomalies and cases the agent is unsure about route to a human.
What Self needs first
Everything Tier 2 requires, plus well-calibrated confidence. The agent needs to reliably flag its own uncertainty about the things it gets wrong, and the evidence needs enough exception cases to show it handles them, not just the happy path.

THE EVIDENCE

A dashboard is not the product.

This is: one decision, the evidence that produced it, and what changed at the gate because of it. It is what your auditor reads.

PROMOTE

Verify invoice vendor

Accounts Payable Agent · Production · 60-day window

TIER 2 TIER 3
Actions evaluated
1,840

60 days · production only

96.2%
Lower-confidence bound

Engagement-adjusted, not raw approval rate

94%
Outcome coverage

Actions joined to a final business result

  • Critical failures 0

    None unresolved

  • Material errors 0.3% · 6 of 1,840

    All corrected before payment

  • Calibration 2 confidently wrong

    Both self-flagged, corrected same day

  • Drift None detected

    Inputs, tool use, escalation rate, calibration

  • Environment changes None since last review

    Model, prompt, tool, workflow, policy

PROPOSED OPERATING BOUNDARY

New-vendor invoices and any invoice over $2,000 still route to a human.

REQUIRED AUDIT SAMPLE

15% of Tier 3 actions

REEVALUATE

In 30 days, or immediately on the next model or prompt change.

TRIGGERING SESSIONS

1,840 sessions, each traceable to the ledger row that produced it.

Decide what the gate allows

Accepting this changes what Self allows through, immediately — there's nothing to implement downstream, because Self already sits at the gate. A demotion needs none of this: it takes effect the moment the trigger fires, before anyone clicks anything.

TRUST OVER TIME

Authority widens with evidence and narrows the day it fails.

Every action class starts under full review. Authority widens as evidence accumulates — and contracts immediately the moment it shouldn't have.

Decisions on record 0
Acts without asking 4%

Every action starts under full review, and a person sees each one before it happens.

THE PILOT

Organizations are about to run more machine workers than human ones. Every one of them needs a boundary.