Agent Tiering / Inherent Risk Classification
Work out how much governance an AI agent actually needs, from what it touches, what it can do and what could realistically go wrong, not a guess.
No form, no email, the full pack as a zip.
The problem this solves
Every AI agent your organisation deploys gets governed the same way, by default, because nobody has a repeatable way to tell which ones actually carry more risk than others. A CV-screening agent that only drafts suggestions and one that auto-sends rejection emails to candidates look similar from the outside. They are not the same governance problem, and most organisations have no structured way to tell the difference before deployment, only after an incident.
Everything gets the same sign-off process, which trains people to route around governance because it's disproportionate for low-risk work.
Everything gets the same light-touch process, which lets the genuinely high-risk agents hide among the low-risk ones until something goes wrong.
Why now
AI laws worldwide are converging on the same idea: agents that make consequential decisions about people, employment, monitoring, education, credit, need to prove they're governed. The specific deadlines keep shifting; several have already been delayed or narrowed since they were first announced.
What doesn't shift is the underlying gap. Most organisations still can't say which of their agents can take an action that affects a real person, whether that ability was ever reviewed, or how fast they could shut one off if it went wrong, while agentic AI adoption keeps climbing regardless. Each pattern in this library takes one piece of that off your plate, on a timeline you control.
Sources: Cloud Security Alliance 2026 survey (n=235 enterprise security leaders); Schellman 2026 State of AI Governance Report (n=525); AvePoint 2026 State of AI report.
What you get
You answer nine factual questions about the agent's purpose, data, actions, reach and worst realistic outcome, and the answers place it in one of four risk tiers. The risk tier sets how much governance the agent needs: who approves it, how often it's reviewed, what evidence you keep and how closely it's watched. It never gives the agent more autonomy or wider access. If you're not sure of an answer, the table won't guess. It tells you outright instead of picking a tier for you.
The full logic in plain English, plus a version you can run directly. Not locked to Microsoft's tools.
A realistic CV-screening agent, set up two different ways. Same agent, same data. One workflow choice changes its risk tier and its operating mode.
A machine-readable definition: the inputs and their allowed values, the outputs, and what Microsoft Entra, Agent 365, your runtime gateway and your team should do with each result.
The core classification logic is fixed. Specific thresholds, like what counts as a ‘severe’ consequence for your organisation, are yours to tune. Everything else is explicitly marked out of scope.
See it in action
Four risk tiers, from lightest governance to strictest:
- R0 — Low
- Universal controls, sponsor approval, reviewed every 12 months.
- R1 — Moderate
- Adds data-owner approval and error, override and cost baselines.
- R2 — High
- Adds business-owner approval, drift monitoring and six-monthly review.
- R3 — Critical
- Adds named sign-off, independent risk review and review every three months.
Take a CV-screening agent at a 900-employee logistics company. It gets set up two different ways, and most teams wouldn't realise the two setups need different governance:
Configuration A — agent sends the rejection itself
Regulated candidate data, a severe consequence for the candidate, and the agent sends the email itself, which can't be undone.
R3 Critical: named sign-off and independent risk reviewConfiguration B — a recruiter sends it instead
Same data, same agent. The agent only drafts, so its operating mode is A1 Propose.
R2 High: business-owner approval, six-monthly reviewOne implementation decision changes the risk tier by one step and the operating mode by more. A high risk tier doesn't let the agent do more: in Configuration A it still may only propose until someone explicitly authorises more. Judged by gut feel, both setups would probably get waved through as “just a filtering tool.” The decision table catches the difference because it asks what the agent actually does.
Try it yourself
This is the actual decision table, running in your browser, not a mockup of it. Answer the nine questions with a real agent in mind and see which risk tier it lands in.
This runs the same decision logic as the table included in the free pattern, evaluated in your browser. Nothing you enter here is sent anywhere.
What it isn't
- Not a platform or hosted service. Nobody runs this for you — you use it on infrastructure you already have.
- Doesn't decide how much autonomy an agent may use. That's its operating mode, decided by a separate pattern, and a high risk tier never raises it.
- Doesn't enforce anything on its own, and isn't a legal determination under the EU AI Act. Once you have the tier, your governance process, Microsoft Entra and your agent's runtime controls apply it.
No form, no email, the full pack as a zip.
Download the free pattern