FLINZ / The Stories / Allowed

Allowed

Wilma approves a repair of €4.200 without asking anyone. She stops one of €3.900 and puts it in front of a human. The difference is not the amount.

Two files. Two Tuesdays apart. Almost the same number on the estimate.

The first: a three-year-old vehicle, one damage zone, a repair method that follows directly from the damage type, a cost profile that matches more than a thousand comparable cases. Wilma approves it. Books the slot. Informs the driver. Nobody is asked, because nobody needs to be.

The second: the estimate came back a second time, after a first version was disputed. The amount is lower. Everyone is satisfied. And Wilma stops. She assembles what she knows, names the reason, and puts it in front of a human being.

The cheaper file is the one that needs a person. That is not a glitch in the logic. That is the logic.

Amount is not a regime

Someone negotiated. That is the whole reason.

Negotiation is interaction: two parties reading each other, adjusting, deciding how much to give. It is not a calculation with a correct answer, and no amount makes it one. A file where people have been bargaining is not routine, however small the number at the end.

Most systems that claim to govern AI govern it with exactly that number. Under this much, automatic. Above it, a human looks. It feels responsible. It is close to meaningless.

A limit knows nothing about whether a claim is straightforward. It cannot tell a clean repair on a healthy contract from a file where liability is contested, where a report contradicts a statement, or where someone was hurt. It reads one dimension of a claim and treats it as the whole.

The real axis is routine versus complexity. Amount still matters, as one criterion inside a profile, weighed alongside the damage zones, the severity, the repair method, the history. It is never the regime.

Three lanes

Every decision point in a claim sits in one of three lanes.

Green is the routine profile: this kind of case, under these conditions, decided by Wilma alone. Not "probably fine": a written definition of what routine means at this exact step, for this exact customer.

Orange is the default. Wilma prepares, proposes, assembles the context. A human decides.

Red is permanent. No confidence score, no track record, no volume of successful cases moves a decision out of red.

The red list is short and absolute. Anything involving injury. Any file where the classification is in doubt. Doubt is, by definition, the opposite of routine. The borderline zone around total loss, and any case where Wilma would be overruling an expert's technical judgement. Coverage interpretation where the reading is disputed. Anything that changes recoverability itself. And negotiated outcomes.

That fourth one is worth a sentence of its own. A change in liability does not process a claim differently. It changes what the claim is worth. It is not a step in the workflow. It is the amount. Wilma builds the impact analysis and puts it in front of a human. She does not decide it, and there is no version of this platform where she does.

Two gates, both must be green

Sitting in the green lane is not enough.

The first gate asks whether this kind of case may be decided here at all. That is the profile.

The second asks whether this particular file is clear enough. A claim can sit squarely inside a routine profile and still be ambiguous: a photograph that shows too little, a statement that contradicts a form, a detail Wilma reads with less certainty than she needs. Then she stops, regardless of the profile.

Both gates must open. And above both sits a switch that closes a lane immediately, without a release.

Autonomy is earned

A green lane does not open because someone ticked a box in a settings screen.

It opens because it was proven, measured against the exact population the profile itself defines, for that customer, before anything is switched on. No evidence, no lane. Wilma's autonomy is not a configuration option. It is a result.

This is where most AI initiatives quietly stall. The demo has no boundaries, and boundaries are not something you improvise once the files are real, the money is real, and someone has to sign. Governance arrives late, assembled out of logs and good intentions, wrapped around behaviour that already exists.

We drew the boundaries first. The behaviour came after.

The registry

Every decision is recorded together with the rule that permitted it. Which policy, which version, which conditions were met, which lane it ran in.

Which means the question a fleet director or an insurer actually asks has an answer. Not "can Wilma decide this?" That is the question people ask before they have thought it through. The real question is "who decided that she could?"

In most deployments that question has no clean answer. Someone wrote a prompt. Someone set a limit. Someone approved a pilot. The authority is scattered across a system nobody can fully reconstruct.

Here, it is a document. Versioned, in force, with a name on it.

What the boundary is worth

There is a version of AI autonomy that means: it does what it likes and we hope for the best. That is not autonomy. That is abdication.

Real autonomy is narrower and far more useful. Wilma works unsupervised inside a space that someone deliberately drew, and stops (cleanly, legibly, every time) at the edge of it. The value is not in how much she decides. It is in how precisely the line is drawn, and how reliably it holds.

An agent that decides everything cannot be trusted.
An agent that decides nothing is not worth having.

The work is the boundary. So we built the boundary first.


Routine, not amount

Complexity is defined in advance, per decision point. Amount is one criterion inside a profile, never the regime itself.

Red is permanent

Injury, doubt, contested liability, negotiated outcomes. No confidence score moves a decision out of red.

Earned, not configured

A lane opens only when it has been proven on the population its own profile defines.