D3 Security · Security Operations Glossary

What Is Graduated Autonomy?

A standalone glossary definition, part of the D3 Security Operations Glossary.


Definition

Graduated autonomy is the practice of widening a system’s authority one class of work at a time, as its record justifies it, with the boundary always explicit. Autonomy is a dial set on evidence, and never a switch flipped on faith.

Part of the security market sells autonomy as an endpoint: the SOC with no analysts, where the machine closes everything and the people have been redeployed or released. Two tests separate that pitch from production reality.

The first is error cost at volume. A system that is 99% accurate sounds finished, and at 10,000 alerts a day it is wrong 100 times a day and 36,500 times a year, with a fully autonomous loop owning every one of those mistakes. The second is accountability. When the questionnaire arrives asking who decided, on what evidence, and under whose authority, an unsupervised loop has no good answer.

Graduated autonomy is the alternative, and it is how every other consequential automation entered production. Flight control and algorithmic trading both widened their authority incrementally, under explicit limits, with the record justifying each step.

What makes autonomy graduated

Four properties distinguish a graduated model from a single global setting:

  • Per class of work: authority is set separately for different alert types and different actions, because the risk profile differs.
  • Earned by record: the boundary widens when the system’s performance on that class of work justifies it, and the evidence for that is the decision record.
  • Always explicit: at any moment a team can state exactly what the system may do unattended and what requires approval.
  • Reversible: the boundary can be narrowed as readily as it was widened, without a redeployment.

Also see:
Autonomy Modes
Fail Toward a Human

How the boundary should be set

There is an important difference between a boundary set by the risk of the action and a boundary set by configuration somebody has to remember to maintain. The first holds when the environment changes. The second decays quietly.

This is worth a direct question in any evaluation: what exactly can the system do without human approval, and is that boundary set by the risk of the action or by per-customer configuration someone must maintain? A vendor whose answer is a settings page has described a maintenance burden.

Graduated autonomy in Morpheus AI

In Morpheus AI, the recommendation stage works as a copilot with four autonomy modes, so a team sets how much the system does on its own per class of work and widens it as trust accumulates. Actions carry command-risk tagging, which means the approval gate is set by the risk of the command itself.

Underneath that, the properties that make widening safe hold at every setting. Weak evidence never closes an alert, in any autonomy mode. An investigation that cannot get what it needs fails toward a human. When Morpheus is uncertain, it defers to a human. Autonomy in Morpheus is a dial you turn on evidence.

Frequently asked questions

What is graduated autonomy?
Widening a system’s authority one class of work at a time, as its record justifies it, with the boundary always explicit. The dial is set on evidence.

Why not go fully autonomous immediately?
Two reasons. At production volume even a highly accurate system is wrong tens of thousands of times a year, and a fully autonomous loop owns each of those decisions with nobody positioned to catch them. Regulators also expect a per-decision record that an unsupervised loop cannot produce.

What is the difference between graduated autonomy and human in the loop?
Human in the loop describes that a person is involved. Graduated autonomy specifies where the boundary sits, per class of work, and on what basis it moves. It converts a general assurance into a testable setting.

How should the approval boundary be determined?
By the risk of the action itself. A boundary that depends on per-customer configuration somebody must maintain will drift as the environment changes.

Can autonomy be narrowed again?
Yes, and the ability to narrow it without a redeployment is part of what makes widening it safe in the first place.

What evidence justifies widening the boundary?
The decision record for that class of work: what the system concluded, on what evidence, how often it deferred, and what happened on the cases it got wrong.

Does graduated autonomy mean slower adoption?
It means adoption proceeds by class of work, one step at a time. Teams frequently reach broad autonomy on high-volume, well-understood alert types quickly, while holding tighter gates on destructive actions.

How many autonomy settings does Morpheus AI offer?
Four autonomy modes, applied per class of work, with command-risk tagging setting the approval gate by the risk of the command.


Related terms

Autonomy Modes — The settings that determine how much a system does on its own, per class of work.

Fail Toward a Human — The rule that an investigation which cannot get its evidence escalates to a person.

Command-Risk Tagging — Setting the approval gate by the risk of the command itself.

Governed Agentic SOC — The operating model that keeps autonomous triage inside explicit governance.

Autonomous SOC — A security operations center in which routine detection and response work runs without direct human execution.

Further reading

The SOC After the Agentic SOC
Why fail-open matters
Autonomy Modes
Book a demo

Last updated: July 2026