ZAO AGENTIC BUSINESS OPERATIONS FRAMEWORK
Design human–AI collaboration as an operable work system.
ZaoABOF connects business goals to people, AI agents, processes, data, systems and decision rights, forming an operating model that is governable, observable and continuously improvable.
SIX LAYERS
From business value to safe operation, none of the six layers can be skipped.
The framework does not treat “more autonomy” as the goal. Every scenario should choose the lowest sufficient autonomy level that produces value.
Direction & value
Why do it, and how value is verified. Without a verifiable business metric, a scenario does not enter the next layer.
Business capability
Which capabilities carry the strategy and where the gaps are. Agents fill capability gaps, not vacant roles.
Operating model
How process, roles, decision rights and metrics combine. Define what people decide before deciding what AI suggests.
Agentic work system
How people, agents, tools, tasks and exceptions collaborate. Every task has an explicit executor, confirmer and fallback.
Intelligence foundation
Data, knowledge, models, systems and integration. Deterministic rules come before model judgment; the model steps in only where rules cannot cover.
Governance & learning
Permissions, risk, observation, review, scale-up and stop. Stop conditions are written when the scenario goes live.
AGENTIC LEVELS
Choose the lowest sufficient autonomy.
A0–A5 is a scenario design scale, not a company maturity ranking. Risk, permissions and reversibility define the delegation boundary: a scenario can stay at A2 forever if that is where it already creates value.
AI takes no part in judgment or execution; the process is entirely human-driven and systems only record facts.
- AuthorityNo system permissions for AI
- ReversibilityNot applicable
- ExceptionsAll identified and handled by people
AI reads data and produces summaries, explanations, drafts or suggestions; people decide and execute independently.
- AuthorityRead-only; no writes to business systems
- ReversibilityFully reversible - there are no writes
- ExceptionsAI flags uncertain items; people handle them
AI drafts concrete actions and pre-fills parameters; a person confirms each one before the system executes.
- AuthorityRestricted writes; every write needs human confirmation
- ReversibilityCancellable before confirmation; rolled back via the business process after
- ExceptionsMust pause and hand over on any out-of-rule situation
AI executes autonomously within whitelisted actions, thresholds and budgets; anything beyond escalates to a person.
- AuthorityWrites within the whitelist; hard caps on amount, frequency and scope
- ReversibilityWhitelist only admits rollbackable or reversible-impact actions (notify, create task, adjust alert); irreversible actions are excluded
- ExceptionsAny threshold hit stops and escalates; the escalation path is pre-assigned
Several agents complete an end-to-end process under an orchestration layer; people supervise key nodes, not every step.
- AuthorityOrchestrator holds permissions and budget; sub-agents get least privilege
- ReversibilityProcess-level checkpoints and compensating transactions; any failed step returns to the last checkpoint
- ExceptionsIf any agent misbehaves, the orchestrator downgrades to A2/A3 or pauses the process
Runs long-term within explicit KPIs, budget, risk ceilings and automatic stop conditions; people review periodically rather than supervise in real time.
- AuthorityFull process permissions under hard constraints on budget, frequency and amount
- ReversibilityEvery action auditable and replayable; a human override channel is kept for critical actions
- ExceptionsCrossing the risk ceiling triggers an automatic stop (kill switch); resumption needs human authorisation
Scenario lifecycle
From business case to controlled scale-up, every step has a written stop condition.
- OutputOne-page value proposition: problem, metric, target, cost ceiling
- EvidenceCurrent metric baseline and scope of impact
- OwnerBusiness owner
- StopValue cannot be quantified, or no business owner claims it
- OutputReadiness assessment of data, process, permissions and exception mechanisms
- EvidenceData availability and quality sampling; process breakpoint list
- OwnerHead of digital
- StopCritical data is untrusted and cannot be fixed within a reasonable period
- OutputScenario list with an autonomy level (A0–A5) assigned to each
- EvidenceRisk, reversibility, frequency and benefit assessment
- OwnerBusiness and IT jointly
- StopNo scenario still delivers value at the lowest sufficient autonomy level
- OutputPrototype running under control, with an observation dashboard
- Evidence4–8 weeks of run data: hit rate, exception rate, human coverage
- OwnerScenario owner
- StopMetrics miss the threshold, or the exception rate exceeds the preset ceiling
- OutputReview report and a decision to scale, downgrade or stop
- EvidenceMetric change against baseline, and governance cost
- OwnerManagement
- StopValue cannot be reproduced, or governance cost exceeds benefit
NEXT STEP
Bring the operating problem
you most want to change.
Delivery, inventory, operating visibility or a workflow where AI could help. Share your situation and priorities so we can identify a practical next step together.