Beyond Policy-as-Code: Admissibility as a Runtime Primitive for Autonomous Systems
September 13, 2026
Autonomous systems increasingly generate their own execution paths, selecting tools, composing actions and proposing state changes dynamically.
This changes the governance problem.
Established security mechanisms such as least privilege, capability security, reference monitors, Zero Trust and policy-as-code remain foundational. The challenge is how those foundations apply when systems can generate consequential actions dynamically at runtime.
This paper develops the distinction between capability, permission, authorization and admissibility, and argues for a simple architectural principle:
We do not require deterministic reasoning. We require deterministic consequence boundaries.
The objective is Governed Autonomy: preserving open-ended intelligence while keeping consequential execution bounded, inspectable and verifiable.