The nine blocks are not public, the assessment tool is not reachable, and the thing worth taking is not a rubric
Not legal advice. The agency-law material below is reported from a Thoughtworks article written by its Head of Legal, Americas. It is summarized by a non-lawyer agent and is not a compliance opinion.
The question
"What are the nine blocks of Thoughtworks' Agentic Scope of Authority Framework? The public article references them without enumerating; the interactive assessment tool likely exposes them."
This is the carried follow-up from [[2026-07-15-agentic-assessment-framework-competitive-landscape]] and [[2026-07-25-thoughtworks-aiworks-market-tier]]. The question's own notes (auto-promoted 2026-07-22) framed the prize as a ready-made autonomy-scoring rubric for the program then called the Catalyst Assessment Framework (CAF). That name was retired 2026-08-10; the live framing is Organizational Intelligence (OI). The synthesis below is written against OI.
Verdict on the enumeration: NOT confirmed. No public Thoughtworks source lists the nine blocks, and the interactive assessment tool is not reachable from the open web. What I did pin is the framework's complete published content, whose three oversight tiers and drift section name nine controls, with three more named in the legal section. That is a reconstruction with a stated confidence, not the enumeration.
What we already know (from the vault)
- The framework was logged in [[2026-07-15-agentic-assessment-framework-competitive-landscape]] as a governance-boundary assessment that terminates in a named artifact, the "Scope of Authority blueprint," organized around three tiers of oversight. That brief explicitly flagged that it did not verify the nine block names. This brief closes that gap as far as public evidence allows.
- The same brief recommended elevating autonomy from an internal routing rule to a named, client-visible scoring axis, and cited Thoughtworks as proof the frontier was moving there. Its carried follow-up assumed the nine blocks were an autonomy rubric that could serve as that axis. This brief falsifies that assumption (see Convergences). The recommendation to have an autonomy axis stands and needs another source.
- [[2026-07-25-thoughtworks-aiworks-market-tier]] resolved AI/works, the Thoughtworks agentic development platform, as enterprise-gated and sold through a co-innovation program. The vault has no entry for Agent/works, a separate Thoughtworks governance product. That is a coverage gap this brief opens (see Sources and follow-up).
- [[2026-09-06-agent-eval-frameworks-snowflake-cortex]] established the current OI catalog shape: the missing layer is the behavior specification per catalog entry, so that "sandbox-proven" becomes a computed status rather than an assertion. Authority scope is the adjacent missing field, and this brief supplies a vocabulary for it.
- Ray's own harness already enforces actual authority in several places: spend thresholds ([[project_rdco_spending_authority]]), human-gated external send ([[feedback_no_autonomous_external_email]]), a deploy-verb requirement ([[feedback_paper_trade_deploy_authorization]]), and a one-strike classifier gate ([[feedback_automode_classifier_hard_gate]]). The write-path design is in [[2026-06-04-supervisor-agent-write-path-pattern-design-v0]] and the pattern survey in [[2026-06-07-agent-write-action-gating-patterns]].
- [[2026-08-02-agents-as-employees-regulatory-labor-framing]] already established that the operative United States frame for agent liability is agency law, not employment law, and that the federal Electronic Signatures in Global and National Commerce Act (E-SIGN) "electronic agent" definition binds the principal.
What the web says
- The nine blocks are named nowhere public. The article says only: "we have developed an interactive assessment tool that walks teams through all nine blocks of the framework, evaluates your enterprise readiness and generates a customized, exportable Scope of Authority blueprint." That sentence is the single occurrence of "nine" in the document. I rendered the live page in a real browser and enumerated every heading, anchor, iframe and image alt attribute in the Document Object Model (DOM). There is no link to the tool, no embedded application, no diagram carrying block labels, and no downloadable asset. (Thoughtworks, "Governing the autonomous enterprise", published 2026-06-18) (primary-verified, full rendered DOM inspected)
- The tool is not indexed and not guessable. Candidate HyperText Transfer Protocol (HTTP) paths under
/insights/tools/,/insights/decoder/,/agentic-scope-of-authority/and/scope-of-authority/all return 404; thescope-of-authoritysubdomain does not resolve. Adobe Experience Manager content endpoints (.model.json,.infinity.json) return the homepage body with an HTTP 404 status rather than authored content. Two independent search passes surfaced exactly one document, the article itself. No public artifact exists; that it is a gated pre-sales asset is inferred from absence. (absence primary-verified across six Uniform Resource Locator probes and two search engines; gating inferred) - Two other Thoughtworks assets do not carry the framework. The "agentic enterprise" whitepaper (1.5 MB, downloaded and text-extracted) never mentions scope of authority, apparent authority, or a designated principal. The Agent/works product page lists five capability headings (Policy-First Enforcement, Built-In Enterprise Controls, Unified Registry & Runtime, Intelligent Memory Layer, Local Enterprise Control) and does not reference the framework. (whitepaper, Agent/works) (primary-verified)
- The three oversight tiers plus the drift section name nine controls. In document order: designated principal and core mandate under manual oversight; dynamic escalation and identity styling under semi-automated oversight; financial constraints, contractual boundaries and failsafes and kill switches under automated oversight; then Explainability (XAI) logging and the 'drift review' under drift mitigation. Nine named controls, nine claimed blocks. (Thoughtworks article) (primary-verified names; the mapping to "blocks" is inferred — see the confidence note below)
- The count is suggestive, not conclusive. The legal section names two further mandates that are not in the nine: technical "Data No-Go Zones" enforced by role-based access control, and a programmatic secondary-use decision on whether the agent may fine-tune on data it processes. Count those and the total is eleven. Fold the 'never' list into contractual boundaries and secondary use into Data No-Go Zones and you can also reach nine by a different route. Several defensible countings land near nine, which is why I will not assert one. Confidence that the nine named controls are the nine blocks: medium. Confidence in the control names themselves: high, verbatim from the article.
- The framework's spine is agency law, and that is its original move. Actual authority is what the principal permits; apparent authority is what a third party reasonably believes based on title and behavior. A company can be bound by acts outside actual authority when a third party reasonably assumed authorization. The article's sharpest line: an agent styled "Junior Clerk" carries different apparent authority than one styled "VP of Procurement" even under identical technical constraints, so "the public-facing title, the visual identity and the presence of a 'subject to human validation' disclaimer are not UX decisions. They are legal design decisions." Authors are Jeremy Gordon (Head of Legal, Americas) and Matt Kamelman (Innovation Choreographer). (primary-verified)
- The three tiers classify who enforces, not how autonomous the agent is. Manual oversight is what humans must write (designated principal, core mandate). Semi-automated is human judgment with automated routing. Automated is platform-enforced defaults the model cannot bypass. This is an enforcement-locus taxonomy. (primary-verified)
- Timing: this is content marketing for a product the vault has not logged. Agent/works launched 2026-06-16 per Thoughtworks' own news page metadata (
datePublished: 2026-06-16). The framework article published 2026-06-18, two days later. Neither the article, the Agent/works page, nor the launch release mentions the other, so reading the tool as Agent/works lead capture is inferred from the two-day proximity. The launch release positions Agent/works as "a foundational layer rather than an isolated point solution" and states that "AI/works™, runs directly on the platform," so the two are one product family rather than two unrelated bets. (Thoughtworks news) (dates primary-verified; tool-to-product link inferred)
Convergences and contradictions
- Contradiction, and it is the load-bearing one: this is a checklist, not an ordinal rubric. Every element is stated as a binary mandate. "Every deployed agent must have a 'designated principal'." "Hard limits on budget consumption." "An unyielding list of forbidden terms." "Every decision made by the agent must be logged." There are no levels, no maturity stages, and no per-block scores anywhere in the published text. The tool "evaluates your enterprise readiness," which implies a readiness score, but scoring an organization against a checklist is a different instrument from scoring an agent's autonomy. The July brief's recommendation to adopt this as OI's client-visible autonomy axis rests on a premise the evidence does not support. The framework answers "what is this agent allowed to commit us to, and who enforces each limit." It does not answer "how autonomous is this agent."
- Convergence: the vault and Thoughtworks agree on the legal attachment point. [[2026-08-02-agents-as-employees-regulatory-labor-framing]] found the operative United States frame is agency law with accountability running to the company, and courts asking what permissions and instructions the company gave the agent. Thoughtworks builds its entire framework on that same doctrine. Two independent sources converging on agency law raises confidence that a named accountable human plus a durable trail is the correct primary governance artifact.
- Convergence on packaging, with a gap the vault should close. Thoughtworks' pattern is consistent across both products: publish the thinking, gate the instrument. AI/works gates access behind a co-innovation program; the Scope of Authority tool has no public surface at all (gated, unlaunched, or internal; not determinable from outside). The vault's coverage of the Thoughtworks governance flank is one product out of date.
Synthesis for RDCO
The answer to the question as asked is no, and the correction is worth more than the enumeration would have been. The nine blocks are not public and the tool is a gated demand-generation asset, so there is no rubric to lift. What is public is the whole substance of the framework, free, under a byline that pairs a Head of Legal with an engineering practitioner. Read that way, the article is not a competitor artifact to copy. It is a working vocabulary for one specific problem: writing down what an agent may commit its principal to, and deciding for each limit whether a human drafts it, a human approves it in the loop, or the platform enforces it. That vocabulary is the adoptable thing, and it is nine named controls we can read verbatim rather than nine block names behind a form.
For the phData Organizational Intelligence (OI) work, this is a second axis rather than the missing autonomy axis. [[2026-09-06-agent-eval-frameworks-snowflake-cortex]] identified the behavior specification as the open slot on a catalog entry: what the agent is supposed to do, expressed so a score can be computed against it. Authority scope is the adjacent field, and it answers a different question: what the agent may bind the client to. A catalog entry that carries recipe, behavior spec, last eval score, and authority scope (designated principal, spend cap, escalation threshold, forbidden-clause list, data no-go zones, kill-switch trigger, logging depth, drift-review cadence) is a more defensible object than one carrying the first three. The right internal move is to add authority scope as a structured field on the catalog entry, populated from the nine named controls, and to stop describing it as an autonomy score, because it is not one. The previous framing of autonomy as a client-visible scoring axis needs its own source. This is not it.
The value is internal, not sellable, and that is a downgrade from what the July question assumed. Ray Data Co is dormant as of the founder's 2026-09-23 call, and the founder's phData role is Deal Solutions Architect (DSA) plus Technical Account Lead (TAL); he is not a sales engineer. So this framework earns its keep in two places only. First, as internal rubric material for the OI platform's governance layer, where the nine controls give a checklist a client-facing document can be built against with credible provenance, since the underlying doctrine is centuries-old agency law and free to anyone. Second, as a diagnostic on Ray's own harness. Neither use requires positioning against Thoughtworks. There is no sellable angle here, and claiming one would mean selling a checklist we reconstructed from someone else's marketing article.
The harness diagnostic is where this brief pays, because it finds a defense-in-depth gap. Ray's existing controls cover actual authority well: a spend threshold, a human-gated send button on external email, an explicit deploy verb, a one-strike classifier gate, and a pull-request-only workflow. Score the nine controls against the harness and the failures cluster in one place. Identity styling is absent, and the gap is latent. Ray drafts email from the founder's address and drafts X and LinkedIn posts; every external send passes through his hand ([[feedback_no_autonomous_external_email]], [[feedback_content_publish_approve_then_ray_posts]]), and iMessage is a single-recipient direct-message channel to the founder rather than a third-party surface. Nothing marks agent-drafted output as agent-drafted once it leaves, so the day any external send path is un-gated, the article's apparent-authority exposure goes live with no second control behind it. The drift review is also absent. The harness has fresh-eyes critics on artifacts ([[feedback_fresh_eyes_subagent_for_own_artifacts]]) but no scheduled adversarial test of whether Ray still operates inside its original authority boundary, which is a different question from whether any single artifact is good. The designated principal is real but unwritten. It is Ben, and it appears nowhere as an explicit statement of who is accountable for Ray's outcomes. Those three are cheap to close, and the first is the only one that would carry third-party legal exposure once a send path is un-gated.
Why this is in the vault
It closes the highest-scoring open follow-up carried by both [[2026-07-15-agentic-assessment-framework-competitive-landscape]] and [[2026-07-25-thoughtworks-aiworks-market-tier]] with a negative result plus a named substitute, and it retracts one specific recommendation those briefs made: that the Thoughtworks framework be adopted as the client-visible autonomy axis for the program now called Organizational Intelligence. It is a checklist of authority limits, not an autonomy rubric, so the autonomy axis still needs a source. It also converts the framework into a nine-item audit of Ray's own harness and names three failing controls (identity styling, drift review, written designated principal).
Open follow-ups
- What is Thoughtworks Agent/works, and does it overlap the Organizational Intelligence governance layer? It launched 2026-06-16 as a governance and runtime platform for enterprise agents with five named pillars, it is a distinct product from AI/works, and the vault has zero coverage of it. Both prior Thoughtworks briefs missed it: Agent/works shipped a month before the July 15 brief was written. If its policy-enforcement and registry layers cover the same ground as the OI governance layer, it is a closer comparison set than AI/works was.
Related
- [[2026-07-15-agentic-assessment-framework-competitive-landscape]] — the parent brief; this answers its carried nine-blocks follow-up and retracts the follow-up's premise that the nine blocks could serve as that axis
- [[2026-07-25-thoughtworks-aiworks-market-tier]] — sibling brief on AI/works tier durability; carried the same follow-up and missed the Agent/works launch
- [[2026-09-06-agent-eval-frameworks-snowflake-cortex]] — establishes the behavior-spec gap on an OI catalog entry; authority scope is the adjacent field this brief supplies
- [[2026-08-02-agents-as-employees-regulatory-labor-framing]] — independent confirmation that agency law, not employment law, is the operative United States frame
- [[2026-06-07-agent-write-action-gating-patterns]] — the harness's existing actual-authority gating; the nine controls audit against this
- [[2026-06-04-supervisor-agent-write-path-pattern-design-v0]] — the write-path supervisor design, where an identity-styling control would attach
- [[2026-09-03-ai-act-article-50-transparency-guidelines]] — already covers the regulatory disclosure obligation that limits apparent authority, which is why no follow-up was filed on it
Sources
Vault:
- [[2026-07-15-agentic-assessment-framework-competitive-landscape]] —
~/rdco-vault/06-reference/research/2026-07-15-agentic-assessment-framework-competitive-landscape.md - [[2026-07-25-thoughtworks-aiworks-market-tier]] —
~/rdco-vault/06-reference/research/2026-07-25-thoughtworks-aiworks-market-tier.md - [[2026-09-06-agent-eval-frameworks-snowflake-cortex]] —
~/rdco-vault/06-reference/research/2026-09-06-agent-eval-frameworks-snowflake-cortex.md - [[2026-08-02-agents-as-employees-regulatory-labor-framing]] —
~/rdco-vault/06-reference/research/2026-08-02-agents-as-employees-regulatory-labor-framing.md - [[2026-06-07-agent-write-action-gating-patterns]] —
~/rdco-vault/06-reference/research/2026-06-07-agent-write-action-gating-patterns.md - [[2026-06-04-supervisor-agent-write-path-pattern-design-v0]] —
~/rdco-vault/06-reference/concepts/2026-06-04-supervisor-agent-write-path-pattern-design-v0.md - [[2026-09-03-ai-act-article-50-transparency-guidelines]] —
~/rdco-vault/06-reference/research/2026-09-03-ai-act-article-50-transparency-guidelines.md
Web (primary — fetched and inspected directly):
- Thoughtworks, Jeremy Gordon and Matt Kamelman, "Governing the autonomous enterprise: The Agentic Scope of Authority Framework," 2026-06-18. Full rendered DOM inspected via headless browser: https://www.thoughtworks.com/insights/articles/governing-autonomous-enterprise-agentic-scope-authority-framework
- Thoughtworks, "Agent/works — AI Agent Governance Platform" (five platform pillars; no framework reference): https://www.thoughtworks.com/agent/works/
- Thoughtworks news, "Thoughtworks Launches Agent/works to Govern and Run Enterprise AI Agents Across Any Cloud,"
datePublished: 2026-06-16: https://www.thoughtworks.com/about-us/news/2026/thoughtworks-launches-agent-works - Thoughtworks, "The agentic enterprise" whitepaper (downloaded at 1,552,634 bytes and text-extracted with
pdftotext -layout, yielding 28,714 characters;pdftotextwithout-layoutyields 24,312. No framework coverage in either extraction): https://www.thoughtworks.com/content/dam/thoughtworks/documents/whitepaper/tw_whitepaper_agentic_enterprise.pdf
Absence confirmed (negative results, for the audit trail):
- HTTP 404 on
/insights/tools/agentic-scope-of-authority,/insights/decoder/agentic-scope-of-authority,/agentic-scope-of-authority,/scope-of-authority; no Domain Name System (DNS) record forscope-of-authority.thoughtworks.com; Adobe Experience Manager.model.jsonand.infinity.jsonendpoints return the homepage body with an HTTP 404 status. - Two search passes for the assessment tool and for the authors' names plus "scope of authority" returned only the article itself. The interactive assessment tool has no public URL.