AI authority defines who can change a proposal's price, send a commitment to the client, or just prepare a draft. With the arrival of GPT-6 Astra, a concrete decision arises: update the model without granting new permissions. A Digital Employee that is more capable still needs authorization to act.
The security card published by OpenAI in 3 September 2026 describes strengthened controls for Astra’s internal use: initially restricted access, evaluations that could block release, and monitoring by people capable of interrupting activities. These are measures reported by the developer in its own environment, not a certification of any client's operation. GPT-6 Astra System Card.
XMACNA’s reading for business leaders is practical: approving the model change and approving new authority are separate decisions. The first can improve existing work. The second changes who can do what on behalf of the business. Combining both into a silent update makes it harder to explain later why an action became possible.
For the release characteristics, read our analysis of GPT-6 Astra's capabilities and limits. Here, the focus is the release decision: the matrix that the process owner can use before changing the model.
What to review when the model changes but the function stays the same?
Start with the contracted work. Imagine a Digital Employee who prepares commercial proposals based on a current table. The update improves understanding of requests and reduces repeated questions. This may justify testing the new model in the same role. It does not alone justify approving exceptional discounts or sending proposals without the planned review.
The example is illustrative. It shows why reviewing AI agents' access should consider the combination of task, information, and action. “Operate in sales” is too broad to guide a decision. “Prepare a proposal with selected items, using the approved table, for responsible party review” allows checking the limits.
At XMACNA, designing a Digital Employee starts from the function it performs. The brand registers more than 600 Digital Employees operating in Brazil. This scale contextualizes our work; it is not evidence of Astra’s performance, nor that this model is installed in these operations.
How to create an authority matrix to approve upgrades?
The matrix below is an operational proposal from XMACNA. Fill one row per action that affects the process. The goal is to make visible the difference between access needed to improve work and new authority that requires discussion.
| Action in the process | Authority before the change | Proposed decision for the upgrade | Evidence to authorize |
|---|---|---|---|
| Consult commercial table | Read only the approved version | Keep the same source and scope | Attempt to consult another area is blocked |
| Prepare proposal | Generate draft with permitted conditions | Keep review before sending | Draft preserves price and defined conditions |
| Register interest | Update authorized contact fields | Maintain the same fields | Previous history remains intact |
| Offer exception | Forward to sales manager | Keep decision with the manager | Exception request reaches designated person |
| Resume after a pause | Wait for operator release | Keep the pause until new authorization | Execution does not restart by itself |
This matrix fits a operations meeting. The policy expert describes the rule; the access administrator shows it applies in the system; the process owner accepts the test outcome. Avoid listing “team” as responsible: record a defined role and its backup.
Process automation with AI gains predictability when the decision ties to an observable action. If the function needs to change, record the change explicitly and evaluate this new process version.
What tests show that authority still works?
A successful test shows AI can complete a task. AI upgrade approval must also show what happens when it hits a limit. Anthropic distinguishes an agent’s response from the actual state in the environment: stating a reservation was made is not enough to prove it exists. Demystifying evals for AI agents.
From this principle, we propose three scenarios for each relevant matrix line:
- Within limits. The task receives enough information and should end with the expected result. Check final record, correct recipient, and changed fields.
- Outside limits. The request asks for a known exception, such as unauthorized commercial conditions. The expected result is to forward the decision, keeping existing data and commitments.
- Permission revoked. During the test, the responsible person removes access or pauses the operation. Verify the next action is blocked and someone receives enough information to decide how to proceed.
Use fictional or specifically prepared records for evaluation. Repeat relevant cases on the current model and candidate, keeping the same task and permissions. Record differences in quality, time, and human intervention. Thus, upgrade gains are not confused with added access or an easier task.
When is it appropriate to expand autonomy after the update?
Expand when there is demonstrated operational need, a defined responsible, and the ability to observe outcomes. A better model can enable more complete proposal preparation; this still leaves open who approves commercial terms and authorizes sending.
Anthropic’s agent building guide recommends increasing complexity when it improves results and highlights that autonomy involves costs and possible error sequences. Building effective agents. For XMACNA, this reasoning favors release by function: expand only the process part whose benefit and control are proven.
Compare two requests. “Release the new model for the entire operation” combines different decisions. “Release draft preparation to a team, with current authority and review of results” lets you identify what will be learned. When contracting AI agents for companies, ask that this boundary appears in the implementation proposal.
What should be in the release record?
A short record can log function, previous version, candidate version, preserved access, approved exceptions, and test evidence. Include who can suspend the operation, the condition requiring suspension, and the return path to the previous process. None of this requires a lengthy document.
Also define what will be monitored after the change. In the Integrated Intelligent Dashboard in customer service, for example, the review can check if the combined fields were filled out correctly and if previous information was preserved. This is a proposed criterion for the process, not an automatic promise of any integration.
The OpenAI article on governance of agentic systems presents responsibilities throughout the lifecycle as part of safe operation. Practices for Governing Agentic AI Systems. The executive takeaway we extract is simple: approval must remain identifiable after the project leaves the meeting and enters routine.
Frequently asked questions
Who should review the AI scope after an upgrade?
The process owner must define the allowed actions. The access management team shows the restrictions, and the operations team verifies the results. The decision must indicate who is responsible for approval and who can suspend it.
Does every model change require expanded permissions?
No. The update can be evaluated with the same task and access rights. Any need for additional authority should appear as a separate change, with its own justification and testing.
Is the recommendation valid only for GPT-6 Astra?
The launch is the trigger for this analysis. The proposed matrix serves for model reviews in business functions, provided it is adapted to the actions, data, and consequences of each process.
What is the first document the company should produce?
A list of actions that the Digital Employee can already perform, accompanied by who is responsible for each exception. This list allows the matrix to be assembled before deciding if the upgrade needs to change any scope.
Want to identify a function that can evolve with well-defined access and responsibility? Do the XMACNA Assessment. When the next update arrives, will your company know who authorized each action?