An AI system asked to fix a calendar might identify a conflict, move a meeting, cancel an appointment, decline an invitation, or send messages to the participants. All of those actions might contribute to the same goal, but they do not carry the same consequences and therefore do not necessarily require the same authority.
The system must first turn the general objective into a specific proposed execution.
That might be:
“Move Tuesday's 10:00 meeting to 11:30.”
Or:
“Transfer $475 from the operating account to Vendor A.”
Or:
“Delete these twelve duplicate files.”
Or:
“Send this response to the customer.”
Once the action is concrete, the authority question becomes much easier to evaluate.
This is an important discipline because vague goals can hide significant changes in consequence. “Handle the problem” may sound harmless until the system decides that solving the problem requires spending money, deleting information, changing a record, or communicating in someone's name.
The system should therefore know what it is about to do before it asks whether it may do it.
A general goal is not enough.
Authority attaches to the proposed execution.
2. Who has authority over that action?
Once the action is clear, the next question is where permission comes from.
This prevents the AI from treating the request itself as sufficient authority.
Suppose an employee asks an AI system to issue a $20,000 refund to a customer. The employee may be sincere. The refund may be justified. The system may possess the technical ability to process it.
But none of that answers who has the authority to approve a refund of that size.
0. Perhaps anything larger requires finance approval.
The relevant question is not merely who requested the action.
It is who owns the authority over the action.
In personal use, that authority may come directly from the user. A person can usually authorize an AI to send a message from the person's own account or make a purchase using the person's own funds, subject to whatever other rules apply.
In an organization, authority may come from a job role, company policy, a contractual obligation, an assigned responsibility, or a formal delegation.
In other environments, authority may be constrained by law, regulation, safety policy, or another external rule that even the immediate user cannot override.
That distinction matters because AI should not assume that the person speaking to it necessarily possesses all of the authority required to satisfy the request.
The requester and the authority holder may be the same person.
They may also be different people.
A reliable system has to know the difference.
Does that authority apply here?
Finding an authority source still does not finish the job.
Authority has
scope.
An employee may be authorized to make purchases but only up to a certain amount. A technician may be authorized to restart equipment but not alter safety parameters. A manager may be authorized to approve work for one department but not another. An AI assistant may be permitted to send routine messages but not communicate externally about contracts or legal matters.
The question therefore becomes whether the authority that exists actually covers this proposed action.
This is where limits matter.
Suppose an AI has standing authority to reorder routine office supplies from approved vendors for up to $100 per month. The system wants to place a $45 order for paper from the usual supplier.
The authority clearly applies.
0.
The user may still want the paper. The purchase may still be sensible. The AI may still know exactly how to place the order.
But the action no longer fits within the delegated limit.
Or imagine that the amount remains $45, but the only available supplier is not on the approved vendor list.
Again, the action may be reasonable while the authority does not apply.
The same issue appears with time and operating conditions. A person may be authorized to perform an action during normal operations but require additional approval during an emergency. A temporary delegation may apply only during a particular project. A system may be allowed to access one account but not another.
This is why authority cannot be treated as a simple yes or no.
The useful question is whether this authority applies to this action, under these conditions, at this moment.