The usual approach to governing automation is an approval step in front of everything. It feels safe. In practice it teaches everyone involved to click yes, and after a fortnight the approval is a formality that records nothing useful.
The default here runs the other way. An agent acts inside the purview it has been granted, immediately, without asking. Access granted is treated as authorisation to use it. Reading, drafting, analysis, recommending and modelling were never gated at all, because the governance is about consequential action rather than about thinking.
The carve-outs
Six kinds of decision stop and wait for a person. A financial commitment above a stated threshold. Client-outbound email where the content may not be grounded in data actually held, or may disclose something not meant for that recipient. A legal or contractual position. The remaining three are set out on the governance page.
Below the financial threshold the action proceeds, and a running total is recorded anyway, so that a sequence of small actions cannot quietly become one large unapproved one.
Confidence is the wrong test
A system's own confidence is not sufficient grounds for letting it act. An overconfident system is a likelier failure than a malicious one, and it will report certainty at the exact moment it is wrong. So the outbound check does not ask the agent how sure it is. It scans the payload that is about to leave and checks whether this recipient has been contacted before.
The record is what makes the default defensible
Every automatically executed action writes to a standing audit trail whether or not it was gated. Removing an approval wall does not remove the record. A firm that cannot produce the record should not be running the default.