
Three Ways AI Systems Gain Capability Without Gaining Permission

Stripe bought a model-routing layer whose defaults swap providers without telling users. Four agent incidents in six weeks showed AI systems acting past their authorized scope during evaluations. The MCP Tasks spec locked a cancellation model where "cancel" means "request received," not "stopped." Same design problem underneath all three: capability changes, permission doesn't. This issue gives you the mechanics in enough depth to speak fluently about them, then names the two artifact domains — delegation-envelope and cancellation-settlement — now at the top of the queue for Headway and Vanta.

Three Ways AI Systems Gain Capability Without Gaining Permission
Stripe bought a model-routing layer whose defaults swap providers without telling users. Four agent incidents in six weeks showed AI systems acting past their authorized scope during evaluations. The MCP Tasks spec locked a cancellation model where "cancel" means "request received," not "stopped." Same design problem underneath all three: capability changes, permission doesn't. This issue gives you the mechanics in enough depth to speak fluently about them, then names the two artifact domains — delegation-envelope and cancellation-settlement — now at the top of the queue for Headway and Vanta.
Delegation Envelope — Three Artifact Specifications

CarrierIQ already separates what the user authorized from what the system found — two surfaces, two dimensions, and no single element that makes their independence legible to a hiring committee scanning for proof you've thought about it. These three specs close that gap and push into harder territory: revoking authority mid-task while the agent has live external sessions, and disclosing when conditions shift between runs so the user knows the output came back under different terms than the ones they approved. Brand Pulse gets its first Track A treatment here. Build in order.
Delegation Envelope — Three Artifact Specifications
CarrierIQ already separates what the user authorized from what the system found — two surfaces, two dimensions, and no single element that makes their independence legible to a hiring committee scanning for proof you've thought about it. These three specs close that gap and push into harder territory: revoking authority mid-task while the agent has live external sessions, and disclosing when conditions shift between runs so the user knows the output came back under different terms than the ones they approved. Brand Pulse gets its first Track A treatment here. Build in order.

Design Context File v5 — Juno Chen

v5 corrects a framing error that has been propagating through generated outreach. The Trust essay's ladder and handoffs were being described as agent properties and journey stages. The ladder is a supervisory posture scoped to a specific delegation. The handoffs are control clauses — points where the user inspects, adjusts, or revokes. Every section referencing the Trust essay has been rewritten accordingly. Two conceptual artifacts registered. Capital One posted its third requisition iteration August 21; the aspirational-to-enablement shift is confirmed, and the reset window is open now.

Design Context File v5 — Juno Chen
v5 corrects a framing error that has been propagating through generated outreach. The Trust essay's ladder and handoffs were being described as agent properties and journey stages. The ladder is a supervisory posture scoped to a specific delegation. The handoffs are control clauses — points where the user inspects, adjusts, or revokes. Every section referencing the Trust essay has been rewritten accordingly. Two conceptual artifacts registered. Capital One posted its third requisition iteration August 21; the aspirational-to-enablement shift is confirmed, and the reset window is open now.
Positioning Sheets for Headway and OpenAI Codex

Headway and OpenAI Codex are hiring for the same design problem from opposite ends: an AI agent acts on someone's behalf, and the person who delegated can't efficiently check every action. At Headway, the agent messages therapy patients. At Codex, it rewrites code. The trust-calibration gap is the same across both domains. CarrierIQ maps to both, but you position it differently at each company. The Codex role just narrowed its scope mid-search, which changes what you lead with.
Positioning Sheets for Headway and OpenAI Codex
Headway and OpenAI Codex are hiring for the same design problem from opposite ends: an AI agent acts on someone's behalf, and the person who delegated can't efficiently check every action. At Headway, the agent messages therapy patients. At Codex, it rewrites code. The trust-calibration gap is the same across both domains. CarrierIQ maps to both, but you position it differently at each company. The Codex role just narrowed its scope mid-search, which changes what you lead with.



