Governed autonomous procurement: how it works and what to require
Governed autonomous procurement means software agents execute authorised procurement work inside policies, permissions, approvals and human checkpoints. It differs from automation, which follows fixed scripts, and from copilots, which help a person act. Proconomy implements the model across sourcing, contracts, purchasing, suppliers and quality.
Every vendor says governed. Here is what it has to mean.
The properties a security review will actually test.
Bounded authority
- An explicit permitted-action set per agent
- A value ceiling above which a person decides
- Entity and category scope on every action
- No general-purpose agent with open authority
- Segregation of duties applied to agents
- Authority widened only on reviewed evidence
Human checkpoints
- Supplier award held by a named person
- Contractual acceptance never automated
- Supplier status changes require authority
- Quality containment acceptance stays human
- Any departure from policy stops
- Checkpoints that no configuration can bypass
Evidence
- Every action attributed to an actor
- The rule that permitted each action retained
- Reasoning behind material actions kept
- Overrides distinguishable from approvals
- Retention configured to your policy
- Reconstruction possible years later
What it is not
- Not a copilot that suggests and waits
- Not automation that stops at variation
- Not full autonomy without human authority
- Not a chatbot over a procurement database
- Not orchestration of tools you do not own
- Not a governance policy document
Eight controls. Each one enumerable.
Role, permission, threshold, policy, checkpoint, escalation, override, retention.
| Mechanism | What it has to do |
|---|---|
| Role | Who may act in this entity, plant and category — applied identically to people and agents. |
| Permission | The specific actions an agent may perform, enumerated rather than described. |
| Threshold | The value or risk level at which a decision returns to a person, set per category and entity. |
| Policy | The buying route required for a given combination of value, category, entity and risk. |
| Checkpoint | A decision that always returns to a named person and cannot be routed around. |
| Escalation | Where work goes when it falls outside permitted authority, with context attached. |
| Override | A person may reverse an agent action, and the override is recorded with author and reason. |
| Retention | How long the complete action history is held, configured to your obligations. |
A description of what the practice requires, not a feature list.
One permission model. Tighter ceilings by sector.
Where authority is set lower, by industry.
Aerospace and defence
Every departure from the approved supplier list stops for named authority and is retained for the programme lifetime.
Medical devices
Anything touching qualification scope or a quality-agreement obligation returns to a person.
Automotive
Containment and root-cause acceptance remain human inside the corrective-action sequence.
Industrial equipment
Wider agent authority on MRO and repeat categories, tighter on project sourcing.
Five requirements. In writing, before contract.
A capability description is not a boundary.
- Require the permitted-action set per agent in writing. A capability description is not a boundary.
- Require a demonstration of an action being blocked at a threshold, and see what the approver receives.
- Require an override to be performed and then retrieved from the record with author and reason.
- Require the complete action history for one transaction, in the form an auditor would receive.
- Ask which decisions the vendor believes should never be automated. A vendor with no answer has not thought about it.
Definitions. Asked and answered.
It is an operating model in which software agents execute authorised procurement work inside policies, permissions, approvals and human checkpoints. Autonomy refers to execution; governance refers to the authority that bounds it.
Automation follows fixed rules and stops when reality does not match the script. Governed autonomy handles variation within a permitted boundary, and escalates what it is not authorised to decide instead of failing silently.
Policy definition, permission sets, thresholds, commercial awards, contractual acceptance, supplier status decisions, exception handling and override. Those are configured explicitly rather than left implicit.
No, and Proconomy avoids describing it that way. Autonomy without human authority is neither achievable nor desirable in enterprise procurement, because consequential decisions carry accountability. The model is deliberately bounded.
It stops, records what it observed and which rule it could not satisfy, and routes the decision to the person your escalation path names, with the context needed to resolve it.
Through the four questions audit actually asks: what was the agent permitted to do, what did it do, who approved the consequential steps, and can the decision be reconstructed. The platform answers all four from the record.
Governed autonomous procurement is an operating model in which software agents execute authorised procurement work inside policies, permissions, approvals and human checkpoints. The word governed is doing the work: authority is bounded, consequential decisions stay with named people, and every action is attributable.
Automation follows a fixed script and stops or errors when reality varies. Agents interpret variation and continue within their permitted authority, escalating what they may not decide. Manufacturing procurement is mostly variation, which is why script automation has covered so little of it.
Anything carrying commercial, legal, quality or safety consequence: supplier awards, contractual acceptance, supplier status changes, quality containment and root-cause acceptance, and any departure from policy. These are judgement with accountability attached.
By recording the action against the agent that took it and the specific permission that allowed it, alongside the policy configuration in force at that moment. Attribution alone shows what happened but not whether it was permitted.