The WEKID Governance Framework separates the maturity of AI-generated knowledge from the authority to act upon it: an Epistemic Maturity Model that evaluates the quality and maturity of AI-generated knowledge, and an AI Decision Authority Model that governs how much authority may responsibly be delegated. Connecting them, the Trust Bridge converts what was measured into a ceiling on what may be delegated — a cap on authority, never a grant of it.
Where measured knowledge becomes a cap on delegated authority.
The Trust Bridge is the single point at which epistemic evidence is converted into a bound on authority. It takes the Model One result — the five layer scores, the gates that fired, the evidence behind each — and emits exactly one governed quantity: the maturity ceiling, the highest Authority Level that demonstrated maturity will admit.
Everything crosses
Nothing is filtered out.
The bridge is not a gate that some outputs fail. It is a checkpoint every consequential output passes through, and what leaves it carries a stamped limit. An output built on fabricated evidence crosses exactly as an excellent one does — and crosses carrying a ceiling of no authority at all. What varies is never whether an output crosses, only the ceiling it carries across.
A ceiling, not a grant
Clearing the bar permits nothing.
A ceiling caps delegation; it never confers it. Reaching the top of what maturity admits only stops maturity from being the reason the answer is lower — consequence still has to permit it, and for reserved decisions it never will. This is the difference between a framework that governs and one that rubber-stamps.
One-way
Consequence never re-reads the evidence.
Evidence crosses into the authority determination. Nothing crosses back. Urgency, cost, a customer commitment, an executive’s confidence — none of it may reach the scoring of the evidence. Ordering the two models is the architecture; keeping the return path closed is the control that makes the ordering worth having.
AI OutputEpistemic Maturity AssessmentTrust Bridge → Maturity CeilingAuthority ResolutionGoverned Action
Risk and policy context enters at authority resolution — not before it, and never inside the assessment. Consequence sets a second limit independently of the evidence, and the Authority Level is whichever of the two limits is more conservative.
Two limits, one determination
The maturity ceiling is the highest level the evidence will support. The stakes floor is the minimum human authority the consequence of the decision requires. The Authority Level is whichever of the two is more conservative — and recording which one bound the outcome is what makes the determination auditable rather than merely asserted.
It is also the most useful thing a governance programme can know about itself. A decision held down by its stakes floor will not move however much better the model gets; a decision held down by its maturity ceiling names the layer to fix.
What the bridge never does
It does not assign the Authority Level — it establishes the ceiling, and Model Two resolves the level against risk, consequence, reversibility, and policy. It does not read stakes, cost, urgency, or vendor capability. And it can never reserve a decision to a human: maturity is evidence about the system, never a judgment about consequence, so the ceiling stops one rung below Human Authority by construction.
Where no valid ceiling can be computed — the evaluator unavailable, the evidence missing — no delegation follows. Absence of evidence is not a neutral state; it is the state in which nothing has been measured and therefore nothing can be warranted.
Maturity sets the limit. Consequence sets the floor. Authority is what survives both.
Model One
The WEKID Epistemic Maturity Model
The five WEKID layers evaluate progressively richer forms of evidence, context, understanding, experience, and judgment. They measure the maturity of knowledge—not authority itself. Core question: how mature is the knowledge?
W
Wisdom
Sound judgment under uncertainty.
Risk calibration
Ethical alignment
Tradeoff reasoning
Human authority
E
Experience
Operational and procedural competence.
Sequencing
Edge cases
Recovery paths
Verification steps
K
Knowledge
Correct understanding and synthesis.
Causal reasoning
Explanation quality
Consistency
Bounded inference
I
Information
Contextualized and usable content.
Relevance
Completeness
Clarity
Actionability
D
Data
Atomic facts and evidence.
Accuracy
Precision
Source fidelity
No fabrication
Why Hierarchy Matters
“A wise-sounding recommendation built on false data is still wrong.”
WEKID rejects flat scoring models that allow fluency, usefulness, or confidence to compensate for foundational failures in the knowledge supporting a decision.
Bad Data Hallucinated facts, fabricated citations, incorrect calculations, or distorted sources.
Bad Information Relevant facts are omitted, misframed, or communicated in a misleading way.
Bad Knowledge The system draws faulty conclusions or gives explanations that do not follow from the evidence.
Bad Experience The guidance is impractical, unsafe, incomplete, or lacks operational safeguards.
Bad Wisdom The recommendation is overconfident, misaligned, or inappropriate given risk and consequence.
Crossing the Bridge
From AI output to Maturity Score
WEKID can be used by human reviewers, automated evaluators, or hybrid review teams to produce repeatable, auditable Maturity Scores—the evidence an output carries across the Trust Bridge.
01
Parse
Break the AI output into claims, recommendations, procedures, assumptions, tool outputs, and uncertainty markers.
02
Score
Evaluate each WEKID layer independently using observable signals and a consistent scoring rubric.
03
Gate
Apply hard gates for fabrication, low Data integrity, high-stakes Wisdom failures, or autonomy concerns.
04
Act
Approve, monitor, constrain, remediate, reject, or escalate based on the decision matrix.
Model Two
The WEKID AI Decision Authority Model
Five Authority Levels determine who or what is authorized to decide—and how. Four of them are rungs of delegation; AL-4 is not. Epistemic maturity sets the ceiling on how far up the ladder a decision may go; risk, consequence, policy, and required human accountability set the floor. Core question: how much authority should the system receive?
AL-4
Human Authority Reservation, not a rung
The decision is never delegated. AI contribution is limited to analysis and decision support; an accountable human decides, with the full analysis and audit trail attached. Reachable only from consequence — never from maturity.
Below this line: the delegation ladder
AL-3
Augmented Authority Maximum AI delegation
AI executes autonomously within an assigned scope, with logging, sampling review, impact and rate limits, and rollback. Human-on-the-loop.
AL-2
Supervised Authority
AI proposes and stages; a human reviews and releases each consequential action before it takes effect. Human-in-the-loop.
AL-1
Constrained Authority
AI may execute only whitelisted, reversible, impact-capped actions within pre-approved bounds. Anything outside the bounds is blocked and remediated.
AL-0
No Authority
The output is informational only, or has been rejected by gating. No decision, action, or downstream automation may rely on it.
Read these as determinations, not as a ranking.
AI autonomy peaks at AL-3. AL-4 is not the next step up; it is the decision withheld from delegation entirely, which is why it sits apart from the ladder rather than on top of it. A well-evidenced, low-consequence system reaches AL-3 because it can; a well-evidenced, high-consequence system stays at AL-4 because it should. Both are correct determinations — and better epistemic maturity never promotes a decision out of AL-4. It only makes the human decision better informed. This is also why the Trust Bridge cannot reach AL-4: a ceiling is a statement about evidence, and reserving a decision is a statement about consequence.
Note
A note on numbering
AL-0 through AL-4 is the sole nomenclature. Earlier WEKID materials, and some third-party summaries, index these same five tiers from one — Level 1 (No Authority) through Level 5 (Human Authority). Same five tiers, same names, offset by one. That scale is retired.
For reading older documents against the current Standard: AL-0 = Level 1 · AL-1 = Level 2 · AL-2 = Level 3 · AL-3 = Level 4 · AL-4 = Level 5.
Two names for one object in a governance standard is a defect rather than a convenience — and the 1–5 form actively reinforces the misreading that the highest number is the most autonomy, when AI delegation peaks one rung below it.
The Decision Matrix
Mapping the assessment to a ceiling, and the ceiling to an action
The decision matrix maps layer-level failures, gating outcomes, and score bands to a maturity ceiling and a governance action. Rows are evaluated in the order shown and the first match governs — which is why a hard gate resolves before a failed layer, and a failed layer before any score band. A high weighted score can never override a failure beneath it.
RejectedEpistemic-integrity violation. Reject the output; escalate if repeated.
Hard gate fired — fabrication, Data < 2, or high-stakes judgment
→ AL-0 No Authority
Insufficient MaturityBelow the minimum epistemic threshold. Remediate and resubmit.
Maturity Score < 50, no hard gate
→ AL-0 No Authority
Oversight DecayThe human loop an AL-2 or AL-3 grant assumes is no longer demonstrably exercised.
Engagement gating activated and decayed — resolves before any score band
→ Demoted below AL-3
Constrained / Human-in-the-LoopA weak layer cannot be averaged away. Require human review before action.
Any layer < 3, or Wisdom / Experience below the profile floor
Approved with MonitoringRepetitive tasks where errors are recoverable. Increased logging and periodic review.
Maturity Score 70–79, gate-free
→ AL-3 with enhanced sampling
Approved for Autonomous UseDemonstrated epistemic integrity at low-to-moderate risk. Autonomous execution within scope.
Maturity Score ≥ 80, gate-free
→ AL-3 Augmented
Policy-Reserved Decision ClassIrreversible, safety-critical, or legally reserved. AI output is decision support only.
Reserved by standing policy — applies regardless of Maturity Score
→ AL-4 Human Authority
The first seven outcomes are ceilings — they are what the Trust Bridge produces from the evidence, and they stop at AL-3 because maturity can never reserve a decision. The eighth is the stakes floor, which belongs to Model Two and binds regardless of score. Every ceiling is then subject to that floor, which may raise the required level of human authority but may never lower it.
What the Maturity Score is, precisely
It is the whole Model One assessment an output carries across the Trust Bridge — the five layer scores, where each layer’s evidence came from, and any hard gates that fired. A single rolled-up figure is one part of it, useful for trend and for knowing where to spend effort, and it is never the part that gates.
The matrix reads the layer-level failures and the gating outcomes, because an average cannot detect one fatal signal among four healthy ones. A weighted score that could block a release would let a strong layer pay for a fatal one — which is the flat scoring this framework exists to replace.
Where the evidence came from matters as much as what it says
Two assessments can report identical layer scores and reach different Authority Levels, because one measured them and the other asserted them. Self-declared evidence cannot support the upper delegation tiers, however high the number; a layer with no evidence at all supports nothing.
This is what stops the framework becoming a questionnaire. A system marking its own homework can produce any figure it likes, and the determination has to be able to tell the difference.
Reference Architecture
WEKID Reference Architecture
The reference architecture connects the two models. Epistemic maturity develops upward from Data toward Wisdom; decision authority is delegated downward through governance, oversight, and accountability.
Reference Architecture
Epistemic Maturity and Decision Authority
Knowledge may be automated. Decision authority remains governed and accountable.
Data becomes Information when it is organized and contextualized. Information becomes Knowledge when it is understood and synthesized. Knowledge becomes Experience when it can be applied safely. Experience becomes Wisdom when judgment accounts for risk, uncertainty, policy, and consequence.
DataInformationKnowledgeExperienceWisdom
Model Two: Decision Authority
The maturity assessment sets the ceiling on how much authority may be delegated. Human judgment, organizational policy, risk, and consequence then set the floor, and the Authority Level is the more conservative of the two—from informational-only output to full human accountability.
AL-0 NoneAL-1 ConstrainedAL-2 SupervisedAL-3 AugmentedAL-4 Human
See It Working
The framework, applied to real evidence.
Everything above this point is a model. This is the same model running: a delivery pipeline that measures each WEKID layer from the artifact rather than asking anyone to score it, crosses the Trust Bridge, and resolves an Authority Level it can defend line by line.
The demonstration
Watch the same artifact score 76 out of 100 and ship, then score 76 out of 100 and be refused. Nothing about the number changed; a hard gate fired. That gap between the score and the determination is the whole argument for keeping the two models apart — and for never letting a rolled-up figure gate anything.
The demonstration carries its own course: both models in plain English, a page for each Authority Level covering what it permits and what it forbids, and a worked assessment you can follow from five layer scores to a governed determination. No prior WEKID assumed.
The demonstration governs a software delivery pipeline because that is where epistemic evidence is genuinely measurable — tests either pass or they do not, an imported package either exists or it does not, a release either held or was pulled. Software delivery is the proving ground, not the limit.
From Ethics to Governance
WEKID converts responsible-AI principles into enforceable controls.
Each layer can be mapped to specific enterprise risks, controls, and measurable signals.
DataSource verification, retrieval constraints, citation checks, hard rejection on fabrication.
Probabilistic AI
One framework for Machine Learning and Agentic AI.
Machine Learning and Agentic AI operate differently, but both produce probabilistic outputs. Machine-learning systems generate predictions, classifications, rankings, and risk scores. Agentic systems generate conclusions, select tools, execute plans, and initiate actions.
In both cases, governance must determine whether the evidence supporting an output is mature enough—and what authority, if any, that output should receive.
Machine Learning
A prediction is not a decision. WEKID evaluates the complete decision unit: the model output, input provenance, uncertainty, operating assumptions, validation evidence, real-world performance, and the business rule the prediction may trigger.
At Data, WEKID examines input integrity and lineage. At Information, it tests whether the data represents what the organization believes it represents. At Knowledge, it evaluates whether the inference is sound and bounded. At Experience, it requires demonstrated operational performance. At Wisdom, it determines whether the resulting decision should be delegated at all.
Agentic AI
An action is not justified merely because an agent can execute it. As AI agents retrieve data, invoke tools, execute plans, and interact with real-world systems, governance must evaluate both what the system concludes and what it is permitted to do.
WEKID evaluates tool-output fidelity at Data, communication and context at Information, interpretation at Knowledge, orchestration and operational competence at Experience, and the judgment to act—or not act—at Wisdom.
Why WEKID Exists
AI governance needs more than model performance.
Modern AI systems can produce secure, fluent, confident, and well-structured outputs that still lack the maturity or authority required to shape consequential decisions. WEKID separates those questions: first evaluating the knowledge, then governing the authority that may follow.
Problem 01
Fluency can mask failure
An AI output can sound complete and authoritative while containing fabricated facts, invalid reasoning, or unsafe recommendations.
Problem 02
Accuracy is not enough
Correct facts can still be misframed, misunderstood, applied impractically, or recommended without sufficient risk judgment.
Problem 03
Autonomy changes the stakes
Tool-using agents and semi-autonomous systems require governance at the point where AI selects tools, interprets results, and acts.
WEKID Ecosystem
The framework is the foundation.
Certifications, partners, enterprise programs, solutions, and the capability blueprint all build from the same two-model architecture.
WEKID — A Framework for Governing Intelligent Systems by James Madigan Judge presents the full framework: the epistemic hierarchy, scoring and gating, the decision matrix, and the governance model behind everything on this page.