Part 1 established that the graph decides what a set of agents can execute: fan-out and tiering turn a slow chain into a fast fleet. A separate question sits underneath every fast fleet, and enterprises that skip it end up explaining an unauthorized action to a board.
The upgrade that solved a different problem
A regional bank's operations team replaces the small model behind its exception-handling agent with a frontier model. Task time drops from most of a working day to under ten minutes (illustrative). The team calls it a governance win, since the new model also writes clearer explanations of what it did.
Governance stayed exactly where it was. The new model holds no answer for whether it was authorized to release a hold on a flagged account, no record a compliance officer can hand an examiner showing who approved that release, and no authority boundary telling it which actions complete on their own and which wait for a person. It got faster at the same unauthorized move, which means the exposure it inherited now arrives sooner.
Speed and authority sit on different axes. An organization that buys the first and assumes the second came bundled has accelerated its risk while leaving the shape of that risk untouched.
What grants authority
Authority lives in the control plane wired around the model, the same way signing authority on a contract lives in a role the organization assigns. A new hire who drafts contracts at speed earns a reputation. Signing authority arrives separately, decided by people who thought about it.
Human-factors research has already measured what assigned ownership does. In 1996, Mosier, Skitka, Burdick and Heers studied automation bias across two groups, students and commercial pilots in simulation, and found that participants who perceived themselves as accountable for how they used an automated aid were significantly more likely to verify its correct functioning and made significantly fewer automation-related errors. In an agentic stack the supervising human is frequently absent from the step entirely, which leaves the architecture as the only place that accountability can live.
Coral Reef Nodes™ name the enterprise's distributed execution units: a resident model, a context service, an evaluation service, a policy-enforced tool adapter, whatever the deployment requires. Every one of them carries the same six-part Node Contract, and the contract holds whichever model happens to be running inside it:
Identity — which service, model, tool, or authorized operator is acting. Capability — what it may read, propose, transform, evaluate, or execute. Policy — the purpose, data class, locale, jurisdiction, and risk boundary that apply to this run. State — the task state and evidence entering the node, and what leaves it. Authority — what completes autonomously and what waits for a human decision. Evidence — what trace, result, grade, or receipt the node must emit.
Swap the small model inside a node for a frontier model and one of those six moves. Identity, policy, state, authority, and evidence stay exactly where the organization put them, because all five belong to the organization and always did.
Where the boundary sits
Part 1's tiering routed the frontier model to the graph's judgment nodes, the steps that carry synthesis and hold real consequence. Those are the nodes where the authority question sharpens, because judgment nodes propose consequential actions: releasing a hold, approving an exception, committing language a customer will read.
GW Slate™ sits at those nodes as the control plane around the work. It evaluates the proposed action against the node's policy, decides whether that specific action completes autonomously or waits for a human, and on completion writes the receipt: cryptographic, tamper-evident, attributable to the identity that authorized it. The model inside the node can be upgraded, downgraded, or swapped entirely while every one of those properties holds. Authority belongs to the architecture, which is why it survives a model change.
Across the governed workflows we have instrumented, capability upgrades and authority failures surface on completely separate audits, because they are separate properties. Treating them as one is how a faster model becomes a faster liability.
The graph decides what can execute. The architecture around that graph decides what proceeds without a person watching. Buyers evaluating agentic AI vendors ask the first question by default. The second is the one their compliance team will be asked.
GlobalizeWe builds governed execution infrastructure for enterprise agentic work — Manta Graph™ to map the estate, GW Slate™ to control the run, Receipt Rail™ to prove it. Human-at-the-control, cryptographically attributable, built onto the systems an enterprise already runs.
Start from Part 1: Agent Topology: The Graph Decides What Enterprise AI Can Execute