Research — Adaptive Governance for LLM Agents · Lucidrail
Research

Adaptive Governance for LLM Agents

Dynamic autonomy based on capability, provenance and performance.

HYPOTHESIS Agent authority should not be static. It should continuously contract or expand in response to evidence about capability, provenance, performance and risk.

Dynamic Autonomy Envelopes

Conventional authorization answers a fixed question: is this principal permitted to perform this action? For agents, the answer depends on facts that change during a single task — which model is acting, what information it has consumed, how it has performed recently, and how consequential the next action is.

We model authority as a function evaluated at each consequential step:

Aₜ = f(Cₜ, Pₜ, Qₜ, Rₐ, I, T)

Cₜ
Capability — demonstrated competence for the task class
Pₜ
Provenance / trust state of the trajectory
Qₜ
Observed performance, including verification outcomes
Rₐ
Risk of the specific action and arguments
I
Identity — role, organization, responsible human
T
Task and context

The output Aₜ maps to an envelope level — autonomous, monitored, approval required, restricted or blocked — for each action class. The functional form is an open research question; current mechanisms use explicit, auditable rules rather than a learned function.

Status

What exists, what’s being tested, what’s open.

MechanismStatusWhat that means
Cross-step trust propagationAvailableImplemented in the product
Policy replayAvailableImplemented in the product
Capability-aware headroomExperimentalImplemented; thresholds under evaluation
Governed self-improvementExperimentalImplemented; budget dynamics under evaluation
Continuous authority function AₜResearchHypothesis; no results claimed
Workforce-level authority allocationConceptLonger-term direction
Research areas

Open questions we work on.

Adaptive authorizationWhen should authority contract, and how fast should it recover?
Agent identityPrincipals for non-human workers, delegation and sub-agents.
Information-flow governanceTracking trust across tool calls, memory and context windows.
ProvenanceEvidence lineage that is useful to reviewers, not just complete.
Capability-aware permissionsMeasuring capability per task class rather than per model name.
Governed self-improvementSafe budgets for agents that edit their own prompts and skills.
Human oversightApproval load, reviewer fatigue and decision quality.
Agent evaluationEvaluations that transfer to authority decisions in production.
Verifiable executionIndependent confirmation that an action had its claimed effect.
Papers & preprints

None published yet.

Papers and preprints will be listed here with their data and methods when available. We don’t report results before they exist.

Collaborate with us