Documentation / Working with Genie
The autonomy ladder
Every capability Genie holds carries a tier derived from what the action would do if it were wrong.
Four tiers
| Tier | Behaviour | Typical |
|---|---|---|
| Shadow | Proposes, never acts | A capability with no outcome record yet |
| Approve | Waits for a named human | Rebooting a production server |
| Notify | Acts, then tells you | Clearing a stuck print spooler |
| Silent | Acts, appears in the digest | Closing a duplicate alert |
A tier is earned, not granted
Every capability starts at shadow. It reaches a higher tier only by accumulating verified outcomes — and then a named person promotes it. Nothing promotes itself.
Promotion needs a run of genuinely verified outcomes, where verification means an independent check confirmed the effect — not that the action returned success.
Demotion is automatic
If a capability's outcomes degrade across independent windows, its tier drops without anyone intervening. The finding is loud and carries the outcome record behind it.
It carries a re-attempt quota, because a demoted capability generates no evidence to earn its way back and would otherwise be retired permanently by one bad fortnight.
Demotion also gates on variance, not just the average. A capability with a healthy mean and a wide run-to-run spread is degrading, and a mean-based check would pass it.
Two gates, not one
The ladder records what you have decided Genie may do. The client-authorised change record holds what your client agreed you may do.
Both must pass. A client pre-authorisation is a precondition, never a promotion — if the tier says approve-first, it still asks.
Not running it yet? Start a thirty-day evaluation — read-only, on your own estate, no card.
Thirty days · read-only · no card
Run it beside what you already have, against your real clients. It tells you what your tools are reporting that is not true.