L0 — Observe / Read
AI may read only information explicitly available to that agent. L0 does not mean access to every profile, private note, service, project or admin record. Data permission remains separate.
L1 — Recommend
AI may suggest an option, resource, question or next step. A recommendation remains correctable and creates no external effect by itself.
L2 — Prepare
AI may prepare a plan, email draft, document, application draft or proposed action. Drafting is not sending, publishing, submitting, paying or changing an account.
L3 — Low-risk reversible execution
L3 is allowed only when a specific policy authorizes the exact action and it is genuinely low-risk and reversible. The workflow needs narrow scope, evidence, verification and rollback.
L4 — Consequential action
External communication, publication, submission, financial commitment and account-level changes may require L4 treatment. Human confirmation should identify the actual action and scope; vague approval must not become standing authority.
L5 — Restricted
Professional legal judgment, clinical decisions, high-risk financial authority, irreversible destructive actions and sensitive administrative controls remain human/admin/qualified-professional authority. AI may assist preparation where allowed; it does not become the qualified authority.
Reflection
Questions to sit with
- What is the smallest approval level this exact action needs?
- What separate data/tool permission is required?
- What evidence proves correct completion or safe reversal?