The wrong answer to this question is a global switch labeled autonomy. Heidi’s answer is a ladder, climbed per agent, per action class, based on track record.
The ladder
An agent starts by watching and suggesting: it sees the work and proposes, a human executes. Good work earns the draft tier: the agent prepares the artifact, a human approves and sends. Proven agents reach act with undo: they execute directly, every act recorded with a receipt and reversible. A correction moves an agent back down. The record of approvals and clean runs that earned each tier is visible, not vibes.
The limit you set
Every agent has a ceiling set by the owner that no amount of earned trust overrides. If you cap an agent at draft, it drafts, forever, until you say otherwise.
Some things always wait for a human
Action classes with high blast radius are gated by class, not by track record. Outbound messages to real people, for example, default to draft-and-confirm: they are treated as not undoable, because you cannot unsend what someone already read. Tools that require confirmation are refused on the raw API path entirely and only run through the agent path where the confirmation flow is enforced end to end.
Automatic never means invisible
Whatever the tier, every action lands in the Ledger with a receipt, every attempt is on the record, and anything reversible can be undone. Autonomy in Heidi is earned permission plus permanent evidence, not absence of oversight.