Layer 2 — The problem
AI can now execute real-world actions, but enterprises still express authority in documents, approvals and disconnected systems.
Four symptoms of the same underlying problem, in the order teams usually recognize them — first the thing you have watched happen, last the thing you are afraid of.
01
A policy that exists in a PDF, a spreadsheet or a Jira approval cannot stop the action it governs. By the time a human reads it, the order shipped, the payment cleared, the agent already called the tool.
02
The same authority — who may spend what, on whose behalf, up to which limit — is re-implemented in the storefront, the ERP, the ITSM queue and the agent framework. Four implementations, four drift rates, no single answer.
03
Approval workflows assumed a person between intent and execution. Agents close that gap to milliseconds, so the check has to move into the execution path itself or it does not happen at all.
04
Logs record what happened. They do not record which policy was in force, which version, on what evidence, or why the action was permitted — which is exactly what an auditor, a regulator or an incident review asks for.
Put the decision inside the execution path rather than beside it.
Before AI acts, Decionis decides.
Nothing reaches execution without passing through the decision. That is the whole idea — everything else on this site is how it is done, where it runs, and how you can check that it is true. See all seven canonical diagrams.