AI autonomy
AI That Executes —
Within Guardrails You Control
Most AI tools only suggest. StudAI BOS turns approved plans into governed execution — always within the boundaries you define. A five-tier autonomy model controls exactly how much the AI may do, per module, per action, per risk level, and today every AI-initiated action requires human approval.
Five tiers
The L0–L4 Autonomy Model
Choose the right level of AI involvement for every scenario.
AI is completely disabled. All actions are performed by humans through the standard workflow interface. Used for highly regulated processes where any automation is prohibited.
Human initiates, human approves, human executes.
AI analyzes context and generates recommendations, but takes no action. Suggestions appear in the dashboard or are pushed via notification. Humans decide whether to act on them.
AI suggests. Human evaluates, initiates, and executes.
AI generates an execution plan and submits it for approval. The plan does not execute until a human explicitly approves it — via dashboard, WhatsApp, or browser confirmation depending on risk.
AI plans. Human approves. System executes.
AI prepares the action for one-tap execution with full context, risk assessment, and rollback plan. In the current release every AI-initiated action still requires explicit human approval before it runs — time-bound post-execution autonomy is on the roadmap and disabled in production.
AI prepares. Human approves. System executes.
Reserved for pre-approved, low-risk, high-frequency actions executing within hard spending and scope limits. This tier is disabled in production today: no AI action executes without human approval, and it will only be enabled per organisation after evaluation evidence.
Disabled in production. No approval-free execution.
Guardrails
The governance pipeline behind every AI action
Autonomy without guardrails is recklessness. Every AI action in StudAI BOS passes through a multi-stage governance check before execution.
Cost Limits
Define per-action and per-period monetary thresholds. AI cannot approve or execute transactions exceeding configured limits without human authorization.
Risk Thresholds
Actions are scored by monetary value, data sensitivity, and reversibility. High-risk actions automatically escalate to the appropriate approval tier.
Separation of Duties
The actor who requests an action cannot approve it. The actor who approves cannot be the same as the executor. Enforced cryptographically.
Escalation Policies
Configure time-based escalation. If an approval sits idle for N hours, it escalates to the next authority. No action dies in an inbox.
Approval Chains
Multi-party approval for high-value actions. Configure sequential or parallel approval requirements. Supports quorum-based approval (e.g., 2-of-3).
Rate Limiting
AI is subject to action rate limits per module, per time window. Prevents runaway automation from executing hundreds of actions in a short period.
Configuration
Granular control at every level
Autonomy levels are not system-wide switches. You configure them at three levels of granularity.
Per Module
Keep CRM at L2 (supervised plans) while holding Finance at L1 (suggestions only). Each module can have its own autonomy policy.
Per Action
Within Finance, allow expense categorization suggestions at L1 while keeping journal entries at L2 (supervised). Control at the action level.
Per Risk Level
Approve routine actions under ₹10,000 with one tap. Require WhatsApp confirmation for ₹10K–₹5L. Require browser confirmation with dual approval for anything above ₹5L.
Safety
What happens when AI is wrong?
AI will make mistakes. The question is not “if” — it's “how fast can you detect, reverse, and learn from it?”
Rollback
Every workflow execution generates before/after snapshots. If an action needs to be reversed, the system can restore the prior state. Rollback itself is a new workflow execution — also fully audited.
Receipt Chain
Every action produces an execution receipt tied to the hash-chained audit trail, including the AI plan that proposed it, the governance policy and human approval that authorized it, and the exact data that changed. The full causal chain is preserved.
Blame Trail
Every execution receipt records: Who (or what AI plan) requested the action. Who approved it. Which governance policy authorized it. What data changed. Accountability is never ambiguous.
Continuous learning from failures
When an AI action is rolled back, the system records the failure pattern. Over time, this improves confidence scoring and risk assessment. The AI learns your organization's risk appetite — not from generic training data, but from your actual operational history.
Set your guardrails.
Let AI run the rest.
Start with L1 (suggestion mode) and increase autonomy as you build trust. Every action is audited, every mistake is reversible, and every decision has a receipt.