06-reference/research

thoughtworks agentic scope of authority nine blocks

2026-09-27·research-brief·source: deep-research·by Ray Data Co (deep-research synthesis)
thoughtworksagent-governanceorganizational-intelligencecompetitive-landscapeagency-law

The nine blocks are not public, the assessment tool is not reachable, and the thing worth taking is not a rubric

Not legal advice. The agency-law material below is reported from a Thoughtworks article written by its Head of Legal, Americas. It is summarized by a non-lawyer agent and is not a compliance opinion.

The question

"What are the nine blocks of Thoughtworks' Agentic Scope of Authority Framework? The public article references them without enumerating; the interactive assessment tool likely exposes them."

This is the carried follow-up from [[2026-07-15-agentic-assessment-framework-competitive-landscape]] and [[2026-07-25-thoughtworks-aiworks-market-tier]]. The question's own notes (auto-promoted 2026-07-22) framed the prize as a ready-made autonomy-scoring rubric for the program then called the Catalyst Assessment Framework (CAF). That name was retired 2026-08-10; the live framing is Organizational Intelligence (OI). The synthesis below is written against OI.

Verdict on the enumeration: NOT confirmed. No public Thoughtworks source lists the nine blocks, and the interactive assessment tool is not reachable from the open web. What I did pin is the framework's complete published content, whose three oversight tiers and drift section name nine controls, with three more named in the legal section. That is a reconstruction with a stated confidence, not the enumeration.

What we already know (from the vault)

What the web says

Convergences and contradictions

Synthesis for RDCO

The answer to the question as asked is no, and the correction is worth more than the enumeration would have been. The nine blocks are not public and the tool is a gated demand-generation asset, so there is no rubric to lift. What is public is the whole substance of the framework, free, under a byline that pairs a Head of Legal with an engineering practitioner. Read that way, the article is not a competitor artifact to copy. It is a working vocabulary for one specific problem: writing down what an agent may commit its principal to, and deciding for each limit whether a human drafts it, a human approves it in the loop, or the platform enforces it. That vocabulary is the adoptable thing, and it is nine named controls we can read verbatim rather than nine block names behind a form.

For the phData Organizational Intelligence (OI) work, this is a second axis rather than the missing autonomy axis. [[2026-09-06-agent-eval-frameworks-snowflake-cortex]] identified the behavior specification as the open slot on a catalog entry: what the agent is supposed to do, expressed so a score can be computed against it. Authority scope is the adjacent field, and it answers a different question: what the agent may bind the client to. A catalog entry that carries recipe, behavior spec, last eval score, and authority scope (designated principal, spend cap, escalation threshold, forbidden-clause list, data no-go zones, kill-switch trigger, logging depth, drift-review cadence) is a more defensible object than one carrying the first three. The right internal move is to add authority scope as a structured field on the catalog entry, populated from the nine named controls, and to stop describing it as an autonomy score, because it is not one. The previous framing of autonomy as a client-visible scoring axis needs its own source. This is not it.

The value is internal, not sellable, and that is a downgrade from what the July question assumed. Ray Data Co is dormant as of the founder's 2026-09-23 call, and the founder's phData role is Deal Solutions Architect (DSA) plus Technical Account Lead (TAL); he is not a sales engineer. So this framework earns its keep in two places only. First, as internal rubric material for the OI platform's governance layer, where the nine controls give a checklist a client-facing document can be built against with credible provenance, since the underlying doctrine is centuries-old agency law and free to anyone. Second, as a diagnostic on Ray's own harness. Neither use requires positioning against Thoughtworks. There is no sellable angle here, and claiming one would mean selling a checklist we reconstructed from someone else's marketing article.

The harness diagnostic is where this brief pays, because it finds a defense-in-depth gap. Ray's existing controls cover actual authority well: a spend threshold, a human-gated send button on external email, an explicit deploy verb, a one-strike classifier gate, and a pull-request-only workflow. Score the nine controls against the harness and the failures cluster in one place. Identity styling is absent, and the gap is latent. Ray drafts email from the founder's address and drafts X and LinkedIn posts; every external send passes through his hand ([[feedback_no_autonomous_external_email]], [[feedback_content_publish_approve_then_ray_posts]]), and iMessage is a single-recipient direct-message channel to the founder rather than a third-party surface. Nothing marks agent-drafted output as agent-drafted once it leaves, so the day any external send path is un-gated, the article's apparent-authority exposure goes live with no second control behind it. The drift review is also absent. The harness has fresh-eyes critics on artifacts ([[feedback_fresh_eyes_subagent_for_own_artifacts]]) but no scheduled adversarial test of whether Ray still operates inside its original authority boundary, which is a different question from whether any single artifact is good. The designated principal is real but unwritten. It is Ben, and it appears nowhere as an explicit statement of who is accountable for Ray's outcomes. Those three are cheap to close, and the first is the only one that would carry third-party legal exposure once a send path is un-gated.

Why this is in the vault

It closes the highest-scoring open follow-up carried by both [[2026-07-15-agentic-assessment-framework-competitive-landscape]] and [[2026-07-25-thoughtworks-aiworks-market-tier]] with a negative result plus a named substitute, and it retracts one specific recommendation those briefs made: that the Thoughtworks framework be adopted as the client-visible autonomy axis for the program now called Organizational Intelligence. It is a checklist of authority limits, not an autonomy rubric, so the autonomy axis still needs a source. It also converts the framework into a nine-item audit of Ray's own harness and names three failing controls (identity styling, drift review, written designated principal).

Open follow-ups

Related

Sources

Vault:

Web (primary — fetched and inspected directly):

Absence confirmed (negative results, for the audit trail):