Every AI product sits on a spectrum from "suggests next action" to "achieves outcomes independently." The mistake is choosing the wrong point on the spectrum for what the user trusts the system to do today. Too much autonomy too early breaks trust; too little leaves value on the table.
Both failure directions are expensive, but they are not symmetric. A product that under-automates loses some value per task and can recover by promoting later. A product that over-automates and sends one wrong email to one real customer loses the account's trust in an afternoon, and demotion never rebuilds it: users who have watched an agent fail at rung five do not settle back comfortably at rung three. They leave. Which is why the spectrum has to be climbed from below.
The five rungs
1. Inform: the system surfaces relevant information. 2. Suggest: it proposes specific actions. 3. Draft: it executes, awaiting approval. 4. Act with audit: it executes and logs; the human reviews after. 5. Act autonomously: it executes within bounded authority, escalates exceptions.
The rungs are not product tiers; they are per-action states. A mature product runs different actions at different rungs simultaneously: categorising an inbound email at rung five, drafting the reply at rung three, and issuing a refund at rung two, all in the same workflow. Teams that assign one autonomy level to the whole product either strand safe actions at low rungs or drag dangerous ones to high rungs.
How to choose the right rung
Match the rung to two things: how reversible the action is, and how much the user has watched the system succeed at the rung below. Reversible actions can ship at higher rungs sooner. High-stakes irreversible actions stay at lower rungs longer. Earned autonomy outperforms claimed autonomy every time.
Both variables are measurable, so the promotion decision does not have to be a vibe. Reversibility: can this action be undone in one step, within one minute, by the user alone? If not, treat it as irreversible. Earned trust: what fraction of the system's rung-three drafts does this user approve without edits? Below roughly 80%, promotion is premature; above 95% sustained for weeks, the approval step has become a rubber stamp and is now pure friction. The band between those numbers is where the promotion conversation belongs.
The shipping pattern that works
Launch at suggest. Watch the suggestions get accepted. Promote to draft when acceptance is high. Add act-with-audit for the boring, repeatable cases. Expand the act bounds slowly, with explicit user opt-in. The product matures up the rungs, in lockstep with trust.
Two design details do most of the work. First, promotion is always visible and always opt-in: the product proposes ("you have approved the last 60 of these unchanged; want us to send them automatically?"), the user accepts, and the setting shows its current rung forever after. Silent promotion, however well-intentioned, reads as the product exceeding its authority, and one discovery of it poisons every rung. Second, every autonomous action carries its own undo and its own log entry. Rung five without a one-click reversal path is not autonomy; it is liability with good marketing.
What to instrument
Four numbers per action type: acceptance rate at suggest, edit distance at draft, exception rate at act, and time-to-detection when something goes wrong. These four tell you which rung each action has earned, and they give enterprise buyers the thing they actually ask for in security review: evidence that the system's authority is bounded, monitored, and revocable. The autonomy spectrum is not just a product framework; documented honestly, it is a sales asset.