A humanoid robot on a shared floor needs different controls than an agent drafting copy. This compass derives the fitting oversight regime from three properties you can actually check, then turns that verdict into a concrete, standards-referenced compliance checklist you can work through and export. Every step of the derivation is shown, and the model is grounded in publicly available standards.
Pick an example as a starting point, or set the values yourself.
A continuous risk field. Vertically the autonomy window A, horizontally the oversight regime K. The surface shades from acceptable to not defensible; the marker sits at your deployment with its recommended regime. Hover to read any point.
Derived from run time, environment, and reach.
The controls below are the ones this deployment triggers, mapped to their source clause in each framework. Set a status per control and add evidence; the readiness score and gap count update live. Only controls relevant to your profile are shown.
| Class | Autonomy window A: unsupervised run time in one stretch |
|---|---|
| A1 | Single step, every result is reviewed before it takes effect |
| A2 | Short action chains in the range of minutes |
| A3 | Multi step tasks running up to roughly an hour |
| A4 | A full shift with no intermediate check |
| A5 | Continuous operation across days |
| Class | Oversight regime K: from tight control to loose review |
|---|---|
| K1 | Every action approved in advance by a named person |
| K2 | Approval required for critical and irreversible actions |
| K3 | Continuous monitoring with the ability to intervene at any time |
| K4 | Oversight by exception, alerts only on deviation |
| K5 | After the fact review based on logs |
| Step | Calculation |
|---|---|
| Autonomy window A | taken directly from the run time slider, A1 through A5 |
| Risk load R | (environment level minus 1) plus reach points: read only 0, changes state 1, moves physically 2, can injure people 3 |
| Tolerance | R 0 to 1: residual risk up to "elevated" is acceptable. R 2 to 3: up to "watch". R of 4 or more: only "acceptable". |
| Recommended K | the loosest regime whose risk cell still stays within tolerance |
| Edge case | if even K1 exceeds tolerance, the deployment is not defensible as configured. Shorten the run time or narrow the reach. |
| Normative source | How it is used here |
|---|---|
| NIST ALFUS framework | autonomy as the interplay of task complexity, environmental complexity, and human independence |
| NIST AI Risk Management Framework 1.0 | Govern, Map, Measure, Manage subcategories as checklist items |
| EU AI Act (Reg. 2024/1689), Ch. III Sec. 2 | high-risk obligations, Art. 9 to 15, with Art. 14 human oversight |
| ISO/IEC 42001:2023 | AI management system clauses and Annex A controls |
| ISO 12100 / ISO 10218 / ISO/TS 15066 / ISO 3691-4 | machinery and robot safety for systems that move or can injure |
| SAE J3016 | analogy for graded autonomy and handover to a human |
The weightings and the control mapping are a reasoned engineering choice, not a normative text. Both live in the source and can be adjusted without changing the structure.