Intelligence Is Cheap. Permission Still Has to Be Built by Hand.


Toyota did not win the manufacturing wars of the 1980s because it had a better factory. American plants ran comparable equipment, comparable tolerances, often the same suppliers. Toyota won because it redesigned who had permission to act.

In the 1970s, Toyota gave line workers something most manufacturers would have considered reckless: the authority to stop the entire production line. The worker who pulled the andon cord wasn’t the most senior person in the building. They weren’t in a meeting with the plant manager. They were usually just the person standing closest to the defect, the one with the least formal power and the most immediate information. The andon cord was never a productivity tool. It was an authority architecture, a decision about who gets to act on what they see, without waiting for someone above them to see it too.

American manufacturers spent the better part of a decade copying the visible parts, the kanban cards, the quality circles, and mostly failed, because what they were copying wasn’t the actual advantage. The advantage was the redesigned permission underneath it, and permission doesn’t show up on a factory tour.


A Second Proof, Twenty Years Later

I’ve written before about Desktop Underwriter, the automated mortgage underwriting system Fannie Mae shipped in 1995. The value didn’t come from software that could evaluate a loan file faster than a human. Every competitor could eventually buy comparable software. The value came from what Fannie Mae attached to the system’s output: a waiver, relief from having to re-verify certain judgments the system had already made, provided a lender’s own data and documentation held up. That’s not automation. That’s an institution redesigning who could decide, who carried the risk when the decision was wrong, and how exceptions got handled, around a machine’s output.

Same mechanism, different industry, twenty years apart. The technology was necessary in both cases. It was never what got captured. What got captured was the permission architecture built around it, and I’ve called that capture Default Capture before: the winner is never whoever owns the technology, it’s whoever owns the constraint the technology creates downstream of itself.

AI is about to run the same test a third time.


The Question That Actually Matters

Most of the AI conversation happening in boardrooms right now is stuck on one question: can the model reason well enough to be trusted?

That’s the easy question, and the mortgage industry answered its version of it in 1995. The harder question, the one that actually determines whether an enterprise can act on what its systems produce, is different:

Can the organization allow the model to act?

Every technology transition creates a new abundance somewhere. The winners are never the organizations with the most of the newly abundant thing. They’re the ones that redesign permission around whatever became the constraint instead, before the market redesigns it for them, on someone else’s timeline.

That’s not a technology question. It’s the same question Toyota answered on a factory floor and Fannie Mae answered in a rulebook. Most enterprises haven’t answered it at all. They’ve bought the equivalent of the andon cord and left it bolted to the wall, unconnected to anything.


The Pilot Trap

Walk into almost any large enterprise right now and you’ll find the same three things: an enterprise AI license, a dozen point-solution pilots, and a Center of Excellence generating slide decks about theoretical time savings.

The demos are genuinely good. That was never the problem. The problem is that the company is putting a new engine into an old transmission. Every output still moves through the same approval chain built when the model needed supervision to be trustworthy. Every exception still follows the same escalation path designed for a system that used to be wrong a lot more often than it is now.

The model got dramatically better. The org chart didn’t get the memo. That gap is where the money goes to die, not in model cost, in the friction of an organization still authorizing decisions the way it did when authorization was the only safety mechanism available.

I don’t think this is a technology adoption problem. It’s an Organizational Rewiring Latency problem, and it’s a particularly nasty one, because unlike most of the shifts I’ve written about, this one doesn’t announce itself as a crisis. Nothing breaks. The pilots keep running. The demos keep landing well in the quarterly review. The company just quietly stays exactly as slow as it was before, with a much more expensive engine attached to the front of it.


The Blast Radius Problem

I’ve written before about the Law of Migrating Scarcity: when technology makes something abundant, value doesn’t disappear, it moves to whatever the abundance can’t dissolve. For decades, enterprise intelligence was that scarce resource, so companies built permission systems that assumed it would stay that way, slow, expensive, routed through whoever in the hierarchy had the most of it. Permission itself was never the scarce thing. It didn’t have to be. It only had to keep pace with a world where a decision moved as fast as the human hierarchy that had to bless it.

That world is ending. Models are commoditizing on schedule, the same way the underlying intelligence is, and the permission system built around its old scarcity is what’s left standing as the constraint. Permission isn’t becoming scarce out of nowhere. It’s being exposed as the bottleneck it was always going to become, the moment the thing it was rationing stopped being rare.

The advantage now belongs to whoever builds the clearest architecture for what a system is allowed to do without a person in the loop, and what still requires one. Within the decision and operational layers of that architecture, most companies still have exactly one lever: human review, on or off, applied uniformly regardless of stakes or track record. A usable version isn’t a single switch. It’s three tiers.

Tier 1, human-in-the-loop. The system recommends, a person decides before anything executes. High-consequence, low-frequency, hard-to-reverse decisions belong here, regulatory filings, large pricing exceptions, anything with real legal exposure attached.

Tier 2, human-on-the-loop. The system decides and acts, a person monitors and can intervene inside a defined window before the consequences compound. Most operational workflows land here once you’ve actually built some track record with the system.

Tier 3, human-out-of-the-loop, bounded. The system acts autonomously inside an explicit blast radius, a capped dollar amount, a reversible action, a pre-cleared category. A person audits the pattern, not the transaction.

Toyota never gave a worker unlimited authority. They could stop the line. They couldn’t redesign the factory, renegotiate with a supplier, or change the product roadmap. The authority had a blast radius, which is exactly what these tiers are designing. They’re a tool for two of the five layers I’ve written about before, decision permission and operational permission, not a replacement for the other three. A perfectly bounded Tier 3 can still fail if whoever audits it shares the same blind spot the system does, or if the outside world, regulators, customers, counterparties, never extends the market trust the internal architecture assumed it would have.

The actual design work isn’t picking a tier once and moving on. It’s the mechanism that promotes a decision from Tier 1 toward Tier 3 as the system earns trust in that specific domain, and demotes it the moment it doesn’t, the same kind of circuit breaker I’ve argued multi-agent systems need for cost, applied here to authority instead of spend. Almost nobody has built that mechanism.

Toyota’s cord and Fannie Mae’s rulebook both had an advantage this version doesn’t. A violation was visible. A worker could see a defect. An underwriting file either met the rule or it didn’t. A model that’s slowly drifting in quality doesn’t trip a wire, it just gets quietly worse, and the same review process built to catch it can end up sharing its blind spot, the exact failure I’ve written about in automated underwriting’s own verification layer. The promotion and demotion mechanism above only works if an organization can actually detect drift in a probabilistic system, and that detection problem is harder here than it ever was on a factory floor. Building a Tier 3 that looks bounded on paper without solving that problem first is how the blast radius stops meaning anything.

The reason this becomes a durable advantage, and not just a nice-to-have, is that permission architectures are hard to copy. A competitor can buy the same model. They can license the same software. They can hire the same consultants who hired the same consultants. What they can’t buy off the shelf is the accumulated trust, the operating data, and the specific decision boundaries that let one organization move with confidence while another is still in a meeting arguing about who has the authority to approve the meeting’s outcome.


What Autonomy Actually Costs When You Get It Wrong

It would be dishonest to make this argument without naming what it costs when it’s done badly. Expanding autonomy without a real governance mechanism doesn’t remove risk, it just changes its shape, from slow and visible to fast and compounding. A bad approval chain produces one bad decision at a time, and someone downstream usually catches it. A badly bounded Tier 3 produces the same bad decision at machine speed, thousands of times, before anyone notices anything’s wrong.

That’s not an argument against building this. It’s the argument for building it on purpose instead of drifting into it. The companies that get hurt in this transition won’t be the ones that moved too slowly on autonomy. They’ll be the ones that expanded it without a defined blast radius, without an audit trail, and without a name attached to who owns it when it fails. Tiering, bounding, and auditing is the whole difference between deliberate autonomy and an accident waiting for a headline.


Three Questions Worth Asking This Quarter

If you’re the one accountable for this inside your company, the diagnostic isn’t how many pilots you’re running. It’s:

Where does a decision still require a human sign-off purely out of habit, not because the stakes or the risk actually call for it?

For your highest-volume automated processes, do you have a defined blast radius and an audit mechanism, or just an on/off switch?

Who owns the outcome when a system acts on its own and gets it wrong, and do they know yet that it’s their job?

Toyota moved authority from headquarters to the factory floor. Mortgage underwriting moved authority from individual judgment to an institutional system. AI is going to move authority from human execution to bounded autonomous systems. The technology changes each time. The pattern underneath it doesn’t.

Most companies can’t answer the second or third question today. That gap, not model capability, will separate the companies that become the default this decade from the ones that spend it running increasingly sophisticated pilots.

Published by Vijay Vijayasankar

Son/Husband/Dad/Dog Lover/Engineer. Follow me on twitter @vijayasankarv. These blogs are all my personal views - and not in way related to my employer or past employers

2 thoughts on “Intelligence Is Cheap. Permission Still Has to Be Built by Hand.

  1. ❤️  The problem is that the company is putting a new engine into an old transmission. 

    Don’t know how you’re writing so much…and why I’m reading LOL

    And I often refer my clients to your newsletter as a grounded source of information for the AI conversations they should be having with their teams.

    Hope your well. JULIE FOXCROFT Founder | Executive Coach PCC, CPCC, MsC Applied Positive Psychology and Coaching Motives: RED-BLUE [Performance-People] Top Strengths: Sociable, Adaptable, Option-Oriented M: 778-960-0684 Get Curious – https://bridge2wellbeing.ca/services

    Like

  2. Very well written Vijay and I completely agree with most of your views. It’s my observation as well that companies aren’t able to move beyond Pilots and AI use cases in Business domain are mostly related to suggestions or recommendations which doesn’t change much, apart from AI usage tag. I specially like the proposed 3-tier review framework. Very insightful, thanks for writing.

    Like

Leave a comment