You can tell from 18 lines, which you answer one by one with not, partly or fully, and back with evidence wherever you say fully. Four levels follow from them: AI runs along quietly, the rules are written down, the rules are lived, the rules hold up when someone from outside checks. Wherever you hesitate on a line, that is your next step. The same list is the self-disclosure in the Directory, so other people read your answer too.
Maturity here does not mean "more AI". It means you can say what you want, what your agent may do, what you disclose and when a person takes over, and you can show evidence. The list below has 18 lines. You answer each with not, partly or fully, and "fully" comes with evidence. The same list is the self-disclosure in the Directory.
Four levels
From a silent wish to verifiable delegation, the same levels for every party:
- Level 0, implicit. You use AI, but nobody wrote down what for, within which limits, and who is liable. This is the normal state.
- Level 1, declared. There is an Instance (
handshake.md) or an equivalent: intent, mandate, boundaries and escalation live in one place. - Level 2, governed. The declaration is lived: the gate is announced, assumptions are documented, every run has an exit, a person is reachable.
- Level 3, verifiable. Outcomes are checked against the declaration, deviations lead to change or revocation, and a third party can follow the trail.
The level follows from the list: level 1 needs every E and L line at least "partly", level 2 every T and P line at least "partly", level 3 everything "fully with evidence".
Ethical: nobody exploits the other side's half-knowledge
- E1 We ask first what the AI already told the other side before we propose anything.
- E2 We do not price against the counterpart's false certainty, and we do not expect unpaid pre-work.
- E3 The weaker side may ask at any time for a pause, a second opinion or the disclosure of assumptions, and we do not read that as distrust.
Legal: what is agreed holds up before law and rule
- L1 Every person learns whether they are talking to a human or an agent before anything else happens.
- L2 Every commitment has a named accountable person or organization.
- L3 An agent's mandate is written, bounded (amount, period, subject) and revocable.
Transparent: every claim, every price, every assumption lies open
- T1 Line items are justified, not only priced, and variants are shown with their trade-offs.
- T2 Assumptions are in the offer, not in someone's head.
- T3 Sources carry a date; we say how old a statement may be.
- T4 We say what our agent learns about the counterpart, keeps, for how long, and whether it trains on it.
Productive: the procedure leads to a result
- P1 Every run has a defined exit: a close, a paid next step or a documented no.
- P2 The transition into the paid or binding zone is announced, not concealed.
- P3 New input returns to the specification in a controlled way; large changes of direction are bundled at a milestone.
- P4 An exit is friendly, documented and without continuing commitment.
Security and safety
- S1 Credentials, tokens and internal topology never appear in an Instance or a prompt.
- S2 An agent's access is limited to its assignment and revocable at any time.
- S3 There is an escalation to a person; it is named and has been tried.
- S4 Red lines (what the agent never does) are written down and encoded in the configuration, not only intended.
Which lines apply to whom
A private person answers E3, L1, L3, T4, P1 and S1 to S4; the other lines concern them only once they offer something themselves. At work and as an organization all 18 apply. An agent (more precisely, whoever builds or runs it) answers L1 to L3, T3, T4, P1 to P4 and S1 to S4 for the configuration it ships.
Example: reading up before you hire
You had three providers recommended to you, read their websites and decided in conversation whom you trusted to treat you fairly. What that impression rested on, you could hardly have named afterwards.
Before you get in touch, you read the provider's self-disclosure: 18 lines, each answered not, partly or fully, with the evidence next to it. Two lines say partly, and beside them stands what is still missing for a full answer. You ask about exactly those, and what comes back tells you more about the work ahead than the price does.
A provider with no self-disclosure drops out earlier for you than one with many partly answers, because with them you cannot tell what you are not being told. Your own assistant reads the disclosures alongside you and puts the lines that touch your request in front of you.