How Governed Work Actually Runs

What This Covers

Individual guides explain each control on its own. This page is the connective one: it walks a single piece of work from the moment it is convened to the moment you read the receipt, and names which control acts at each step.

Read it once to get the shape of the system. Every heading links to the guide that owns the detail, so nothing here is a second copy of a fact documented elsewhere.

The one-sentence version

A Workroom holds the work. Its shape bounds what may happen there at all. Its posture decides how hard and how fast a coworker pushes inside those bounds. When the coworker reaches a real decision it consults the corpus that owns that kind of question. When it reaches for a tool, the gate checks authority. What happens is written to a receipt you can review.

Each step can only narrow the one before it. Nothing later in the chain can widen what an earlier step allowed — that invariant is what makes the whole sequence safe to describe in one sentence.

1. The Workroom holds the work

A Workroom is a focused place where authorized people and AI coworkers coordinate toward a named outcome. It is not an open chat channel: it carries a purpose, an outcome, a scope, an accountable owner, an authority level, a sensitivity ceiling, measures, timing, and a rule for when it closes.

Rooms come in two modes. A finite room closes when its bounded outcome is satisfied. A standing room supports recurring work, and each cycle gets its own objective, measures, stop conditions, and structured outcome.

Conversation alone never completes a room. Closing one produces an Outcome Packet built from governed decisions, artifacts, actions, receipts, evidence, and — importantly — the work left unresolved, each item with an explicit disposition.

My Work and Workrooms is the full operator guide.

2. The shape bounds what may happen

A room is convened with a collaboration shape. The shape is the answer to “what kind of collaboration is this”, and it decides which roles must be present before the room may act at all.

Shape What it is for Roles it requires, in order
specialist-alignment A corpus check routed to a qualified specialist before the accountable approver receives the verdict coordinator → specialist → approver
approval-sign-off A specialist prepares evidence; an accountable approver signs off coordinator → specialist → approver
outward-review Something leaving the business under its own name gets specialist review and an explicit send or publish approval coordinator → specialist → approver
change-consequential A consequential change is reviewed and confirmed before it executes coordinator → reviewer → approver
escalation A veto returns to the originating coordinator and accountable owner to accept, block, or amend coordinator → approver
craft-stewardship The standing profession room: specialists curate their corpus and triage findings coordinator → specialist

Two properties matter beyond the role list:

A room that never declared a shape gets a derived one from what it already is — a standing profession room is craft stewardship by definition; launch-readiness work is an approval sign-off; governance and remediation work is consequential. Declaring a shape is therefore a way to be more specific than the default, not a required step.

If the required roles are not filled, the shape reports the gaps and the room is not allowed to proceed on that basis. A missing approver is a stated gap, not a silent pass.

Work shapes and the decision gate covers the four independent shape axes and the code that owns each.

3. The posture sets the pace

Posture is the newer half of the picture, and it is the answer to a question operators kept asking: why is this coworker behaving like this?

Historically a coworker had one proactivity level and one cost/quality/time preference tied to its own identity — the same posture whether it was drafting a note on a Saturday evening or releasing a payroll run on the statutory due date. Identity turned out to be a poor proxy for what a piece of work actually needs.

Posture is now resolved from the work, through one precedence ladder:

  1. Hard policy — data residency, sensitivity ceiling, regulated ceiling. Never relaxed.
  2. The room’s own declaration — an explicit choice made when the room was convened.
  3. Derived — from the shape of the work, the business’s value stream, the clock, and the stakes.
  4. The coworker’s own saved posture.
  5. Organization or activity-family default.
  6. Platform default — Balanced.

Layer 3 is the new one. Three things feed it:

The two rules that make this safe

A derivation may tighten. It may never widen. A derived posture can raise urgency, require an extra approval, or add a verification step. It can never remove one, lower a floor, or relax data residency. Closing time changes how loudly a coworker follows up; it never changes what a coworker is allowed to do.

Some work is never quietened. Security incidents, platform and queue health, and a field appointment already running late keep their pace when the business is closed — because those problems get worse while nobody is looking. The exemption list is explicit and tested.

Every adjustment records why it applied, so a setting that did not take effect explains itself rather than appearing to be ignored.

→ Each room’s Pace and priority panel shows the result and its provenance; see My Work and Workrooms. Per-coworker levels live in Coworker Proactivity.

The priority half

The same posture carries a cost / quality / time preference — the Golden Triangle. It is a preference-to-policy compiler, not a model picker: you express intent in plain terms and it produces explicit policy adjustments against the routing and decision contracts that already exist. It feeds model routing as defaults; an explicit setting and the local-only sovereignty switch still win.

Two properties keep it safe on the shared inference path: it fails open — any error falls back to today’s behaviour — and it is Balanced-inert, so a default posture produces no adjustments at all.

Priority, Outcomes & Calibration covers where to set it, how the kind of work raises the floor, and how to read what actually ran.

4. The corpus decides the question

When a coworker hits a real decision rather than a routine step, it does not improvise and it does not blend everything into one opinion. It routes the question to the scope that owns it. Three scopes, three corpora, three different questions. They are siblings, not a hierarchy.

Scope The question it answers What it reads
WSID — profession How should I, in my craft, do this? The profession’s own corpus of recorded techniques and standards
WWMD — platform What should we do about the platform itself? The kernel principles
WWWD — organization Does this fit the company — mission, market, product, go-to-market? The stances your organization has authored

Routing a question to the wrong scope is the failure this separation exists to prevent. A customer’s business decision must not inherit platform judgment as authority.

Three properties of the profession gate are worth knowing, because they shape how a coworker behaves when its corpus is thin:

That last point is the practical one: corpus coverage is an input to autonomy, not a nice-to-have. A coworker whose profession corpus is empty will keep asking you, correctly.

Decision Perspective for the model; Decision Perspective in Practice walks a real question end to end.

5. The gate checks the tool

Consulting a corpus produces a recommendation. It does not produce permission. Permission is decided separately, when the coworker reaches for a tool.

Every governed tool call is classified into one of three consequence classes:

Classification is not a hand-maintained list of tool names. It runs from the declared consequence on the tool itself, on the central governed execution path, so it covers every governed call. A consequential tool also carries the collaboration shape its use implies — which is how a tool reaching outward pulls outward-review into the picture even when nobody named it.

Two independent checks then apply, and both must pass:

The posture from step 3 and the envelope are one projection, and the stricter of the two wins. A proactivity setting cannot buy autonomy the envelope would deny, and an autonomous envelope cannot act on work whose shape declared that it must be proposed.

Denials come back as named reasons — a missing decision interaction, a missing envelope, a tripped stop condition, a missing verification receipt — not as a generic refusal. A denial tells you what to fix.

The floors nothing crosses

Two hold at every posture, every autonomy level, and every proactivity setting:

A third class joins them where the work is regulated: statutory filing and licensed advice carry a mandatory verification requirement that the posture cannot trade away. For these, verification is not advisory — the action cannot close without the verification receipt on the case.

Identity and Access for the authority model; AI Workforce for tool grants.

6. The receipt is what you review

Every governed outcome writes a receipt: who acted, what they did, why, under whose authority, and what resulted. This is the part most worth building a habit around, because it is where the previous five steps become inspectable rather than theoretical.

Four surfaces read that trail, each answering a different question:

Where the audit trail has nothing to say, these surfaces say so rather than guessing. A stage with no records reads No records yet. A room with no posture of its own reads Running on defaults. That is deliberate: a picture that never disagrees with the ledger is worth more than one that always looks complete.

Known limits

Stated plainly, so nothing here reads as more finished than it is: