HOW IT WORKS
Re-authorize
AG Arch uses Re-authorize when the next valid action is understood, but it lies outside the mandate currently attached to the work.
The distinction from Replan is important:
Replan changes the path inside existing authority.
Re-authorize changes the authority boundary itself.
This is the recovery path where Human Authority becomes directly involved.
Why Re-authorize exists
Autonomous execution needs clear boundaries.
Those boundaries may define:
- which systems may be changed;
- which environment is in scope;
- what kinds of actions are allowed;
- what must not be changed;
- which decisions remain human;
- which higher-risk actions require explicit authorization.
Sometimes execution reveals that the original mandate is no longer sufficient.
AG Arch may know exactly what would solve the problem while also knowing:
The current work is not authorized to do that.
That is not a planning problem and not a capability problem.
It is an authority problem.
AG Arch identifies the exact authority gap
Re-authorize should not mean sending a vague message such as:
“Need approval to continue.”
AG Arch already has the context, evidence, and execution history needed to explain what changed.
It can identify:
- what the current mandate allows;
- what new action is required;
- why that action became necessary;
- which existing boundary blocks it;
- what effect expanding the mandate would have.
This gives Human Authority a concrete decision rather than asking a person to investigate the task again from the beginning.
For example:
The task is authorized to modify the staging service. Evidence now shows that the actual fault is in production. Resolving it requires extending the mandate to the production environment.
That is a specific authority decision.
Human Authority changes the boundary — not the execution details
The role of the human is not to tell the agent every command it should run next.
Human Authority decides whether the autonomous system may cross the newly identified boundary.
The possible decision may be:
- authorize the additional scope;
- authorize a specific exceptional action;
- keep the existing boundary unchanged;
- change the intended direction;
- terminate the work.
Once that decision has been made, AG Arch can return to autonomous operation.
This keeps the human at the authority layer, rather than turning the human into a routine executor.
A new authorization creates a new governed mandate
When Human Authority approves a change, AG Arch converts that decision into an updated governed mandate.
For example, the previous mandate might be:
Modify the configuration of Service A in staging.
The updated mandate might become:
Modify the same configuration for Service A in production, while preserving the existing availability and proof requirements.
The change should be explicit.
AG Arch now knows that the boundary has moved and can use that new mandate for planning, routing, execution, and verification.
The rest of the governance does not disappear simply because broader authority was granted.
Authorization should be bounded to the decision being made
Re-authorize is not intended to turn a narrow permission problem into unrestricted access.
If the system needs permission to restart one production service, the resulting mandate does not need to become:
Do anything necessary in production.
The new authority can remain specific to:
- the action;
- the resource;
- the environment;
- the duration or task;
- the conditions under which it applies.
This allows AG Arch to expand autonomy precisely where it is needed without removing the surrounding controls.
Re-authorize can also reduce authority
The boundary does not always move outward.
Human Authority may decide that new information requires the mandate to become narrower.
For example:
- a previously permitted environment may become protected;
- a risk may be discovered;
- part of the task may be removed from scope;
- a certain class of action may no longer be acceptable.
AG Arch then updates the governed mandate accordingly.
Re-authorization therefore means changing the authority state, not merely granting more permission.
Human involvement remains exceptional
Re-authorize is where the human role is clearest, but it should not become the default path for ordinary execution decisions.
AG Arch should continue autonomously when:
- the existing mandate already covers the required action;
- the system can replan inside that mandate;
- another authorized capability can perform the work;
- additional evidence can be gathered without changing authority.
Human Authority is needed when the autonomous system reaches a boundary that it does not have the right to redefine itself.
This preserves the division:
AG Arch determines what the work needs.
Human Authority determines whether the mandate may change.
AG Arch then continues execution inside the resulting mandate.
Re-authorize is different from Reroute
These two recovery paths can appear similar.
Suppose the current agent cannot perform a production operation.
There are two very different possibilities.
Case 1 — the task is already authorized for production, but this agent lacks the capability.
That is a Reroute problem.
AG Arch needs a different capability.
Case 2 — the agent is technically capable of changing production, but the task is authorized only for staging.
That is a Re-authorize problem.
AG Arch needs a different mandate.
This separation prevents capability and authority from being confused.
Example — changing a system configuration
Continuing the configuration example:
The task is authorized to correct a service configuration in staging.
Execution and observation reveal that staging is already correct.
The actual problem affecting users is caused by the equivalent configuration in production.
AG Arch now knows:
- the original assumption was incomplete;
- production contains the relevant incorrect value;
- fixing production would address the intended outcome;
- the current mandate does not permit production changes.
AG Arch therefore selects Re-authorize.
It presents the authority gap:
The existing mandate covers staging only. Current evidence shows that the incorrect configuration is in production. Correcting the outcome requires permission to modify the corresponding production setting and verify the production service afterwards.
Human Authority can now decide whether that boundary should change.
If authorization is granted, AG Arch creates the updated governed mandate and returns to the appropriate lifecycle stage — usually Plan & Govern, followed by routing and execution.
If authorization is not granted, the system preserves that decision and evaluates whether another valid path exists.
If none exists, the work can move to Safe Stop.
What Re-authorize changes
Re-authorize changes:
what the autonomous system is permitted to do.
The decision comes from:
Human Authority
and becomes:
an updated Governed Mandate.
The execution system does not grant that authority to itself.
Once the new boundary is established, AG Arch can again continue autonomously inside it.
If the mandate is already sufficient but the current agent, model, tool, or specialist is not, the problem is different.
That recovery path is: