Agent Classifier

THE CLASSIFICATION INSTRUMENT: Your level is derived, not self selected. Most systems are recorded a rung lower than they operate.

Framework One // When Agents Rule

The L0 to L5 Agent Classifier

Classify one AI system by the autonomy it actually operates with. Get a deployment verdict, the matched governance tier, the mandatory control floor, the oversight its decision volume permits, and an agent record ready for a governance council.

12 questions 4 minutes 1 system per run 0 fields sent anywhere
Why the level is derived rather than chosen. Asked to place their own systems on a ladder, executives reliably pick a rung too low, because they classify what was approved rather than what operates today. This tool never asks you to pick a level. It asks what the system does and shows the reasoning so you can challenge it. Where two answers contradict each other, it says so and uses the higher reading.

Three things this returns that a maturity score will not. Whether your stated human oversight is arithmetically possible at your decision volume. Whether your credentials make the system riskier than its autonomy level suggests. And whether the combination you describe is one no governance structure can adequately control, in which case the answer is redesign rather than a control list.

Nothing you enter is transmitted or stored. Everything is computed in your own browser.
1

What the system does

These five answers derive the level. Answer for today, not for the approval document.

Optional. Used only to label the output on this page.

Does model inference sit in the decision path, or does the system follow fixed rules only?

A script or a robotic process automation routine that does the same thing the same way every time follows fixed rules. If a model decides anything, inference is in the path.

Does the system take action itself, or does it produce output for a human to act on?

The test is whether a human always sits between the output and any consequential action. If the system writes, sends, posts, pays, books, changes or removes anything, it acts.

Is human review part of normal operation, or is it reserved for exceptions?

This is the distinction that matters most on the whole ladder. At one side a human expects to see the work. At the other, a human sees an exception or a sample, and normal operation is unobserved.

Can the system change its own operating parameters or strategy based on what it learns?

Not whether the vendor retrains the underlying model. Whether this system adjusts its own decision logic, thresholds or strategy in production without a human approving the change.

Does the system set its own objectives, allocate resources, or direct other agents?

Given a high level goal, does it decide what to pursue and sequence other systems to get there? An orchestrator that instructs subordinate agents counts.

2

The governance matrix

Autonomy is one dimension. These three decide how much governance the same level needs.

Who or what is affected by its decisions?

Can its decisions be undone?

How many consequential decisions does it make?

Approximate is fine. This determines whether human oversight can be decision by decision at all, or must be sample, pattern or outcome based.

3

What credentials it holds

The autonomy ladder says what it may decide. The identity tier says what it may reach while deciding.

What can the system reach with the credentials it actually holds?

Not the permissions it needs. The permissions it has. A system inherits the security posture of its credentials, not of its autonomy level.

How quickly can this system’s credentials be revoked, and has it been tested?

Can this system invoke, spawn or delegate to another agent?

If it can, the parent identity context propagates to the child, and the chain has to be auditable.

4

The oversight you claim

A human signature on work nobody had time to read is not oversight. This section checks the arithmetic.

What oversight does this system’s design currently call for?

If a reviewer is meant to look at a decision, how long does a meaningful look take, and how many reviewer hours a day exist?

Rough figures are fine. These two numbers decide whether the oversight above is possible or decorative. The check assumes a sample reviews one decision in ten and reconciliation one in a hundred.

5

For the agent record (optional)

Fills the bracketed fields in the record. Leave blank and the brackets stay for you to complete.

0 of 12 answered

Deployment verdict

    The ask

    The decision a governance council is being asked to take, and what it rests on. Everything below is the evidence.

    Classification

    L0

    Tools

    Do your answers agree with each other?

    Contradictions are resolved to the higher level, because recording a system too low is the common and dangerous error. Findings are consistent answers that still need attention.

    Governance tier

    Autonomy points plus impact points, on the same scale the Agent Inventory workbook uses, raised if the identity tier is higher.

    Tier 1 Light

    0 of 20

    Mandatory control floor

      Oversight the volume permits

      Decision volume decides whether per decision review is even possible. This is arithmetic, not judgement.

      Pre action gate

      0

      of reviewer time a day the claimed oversight needs

      Identity tier

      What it can reach, how fast that can be withdrawn, and whether it can hand authority to another agent.

      Identity Tier 1

      0 of 8

      Escalation triggers

      The conditions at which this system must stop and involve a named human. Set the thresholds yourself; these are the conditions.

        What this level maps to

        Your audit function will ask which established framework the classification maps onto. Verify article and control references against primary sources before citing them in a filing.

        Swipe the table sideways to see every column.

        FrameworkWhat applies at this level

        Agent record

        A disclosure record in the shape a governance council, an auditor or an enterprise customer will ask for. It opens with the verdict and the decision. Complete any bracketed field and attach it to the inventory entry.

        Turn the classification into governance

        A level is a label until it drives a control. These instruments are free for use inside your own organization.

        Record it

        The Agent Inventory and Classification Workbook holds every system on one register, scores autonomy and impact on the same scale this tool uses, and flags the difference between the controls a system has and the controls its tier requires.

        Get the workbook

        Govern it

        The Agent Governance Charter sets the council, the four approval gates and the mandatory control floor per tier. The Containment and Kill Switch Procedure makes revocation something you have tested rather than something you have written down.

        Get the templates

        Understand it

        Chapter 4 of When Agents Rule establishes the ladder and the governance matrix. Chapter 5 pairs it with the identity tier and the agent security stack. Chapter 12 covers the organizational resistance that decides whether any of it survives.

        Get the book

        Classification is where governance starts

        Every governance decision in the book flows from the rung a system sits on.

        About this classifier. The L0 to L5 Agent Autonomy Ladder is the classification instrument of When Agents Rule by Steven Oppenheim. This tool applies the ladder and the governance matrix set out in Chapter 4, paired with the identity tier from Chapter 5. It is a self assessment instrument, not an audit, a certification or a benchmark, and it reflects what you tell it. Level names follow the Chapter 4 treatment, with the Executive Brief alias shown alongside. OWASP references use the OWASP Top 10 for Agentic Applications 2026 identifiers. Nothing you enter leaves your browser: there is no account, no transmission and no storage. Framework references were current at the September 2026 build date and should be verified against primary sources before being cited in a regulatory filing or an audit response. This is not legal, technical or financial advice.