The system keeps records; the work stays with people
Software stores what happened; a person makes every decision and does every task. Most processes in most organisations sit here today — a starting point, not a flaw.
“We run autonomously with AI” costs nothing to say in 2026. There is no ruler for it, so the claim and the reality sound identical. This model measures one thing: what share of decisions in a process completes without reaching a person?
Software stores what happened; a person makes every decision and does every task. Most processes in most organisations sit here today — a starting point, not a flaw.
Automation exists in “if this, do that” form; there is no AI. A person writes the rule and the system follows it faithfully. Fast, but it stops at anything unforeseen.
AI produces suggestions and drafts; nothing leaves without approval. Quality rises, workload does not — because a person still stands at the gate of every output.
The system decides and acts; a person reviews only exceptions and can reverse them. This is the first rung where workload genuinely drops — and the right stop for most work.
The system both decides and executes; a person sets policy and limits, and reviews the audit trail. Suitable for reversible work with a narrow blast radius.
Maturity models usually imply that higher is better. This one does not. Work that cannot be undone or that carries wide impact — moving money, deleting data, processing personal data, committing to an outsider — is deliberately held at S3. Holding it there is not a gap in maturity; it is evidence of it.
The question that reveals an organisation's autonomy maturity is not “how many processes are at S4?” It is this: which processes did you deliberately keep at S3, and why?
Publishing the model without measuring ourselves against it would have been hollow. The table below shows 361's own processes at their measured — not estimated — levels. The weak ones are here too: a table that shows only strengths is advertising; one that shows both is evidence.
| Process | Level | Status |
|---|---|---|
| Lead qualification and nurture | S3 | A form arrives, AI assesses it, a record opens, the team is notified. A person reviews only exceptions. measured end to end · 13/13 checks · 2026-07-29 |
| Funnel measurement and reporting | S1 | Measurement is rule-based, repeatable and now runs on its own daily; the dashboard refreshes without a person. No AI involved, which is why it is not S2. 2026-07-29: put on a schedule — a person no longer starts it |
| Publishing checks (content gate) | S1 | A rule-based gate stops violations before publishing; it is not yet wired into the pipeline automatically. |
| Solution design and POC | S1 | Preparation sits with the system; judgement stays with people. deliberate ceiling: S2 — design is a judgement task |
| Partner applications and onboarding | S0 | When measured, every one of them was dead — written against steps the engine does not have. They were rewritten, the trigger audit is green, and they are now on. The level stays S0: they have not yet been seen running in production. being switched on is not evidence — the level rises on the first real run |
| Compliance and personal data | S0 | Rewritten in the same package. The bulk anonymisation step ships with three safeties: a filter is mandatory, nothing is written if the record cap is exceeded, and the number of rows written is asked of the database rather than assumed. Level stays S0 — the first real run has not been seen. deliberate ceiling: S3 — anonymising cannot be undone, will not be raised to S4 |
| External channel communication | S0 | No social or messaging channel is connected. |
| Customer health and expansion signals | S0 | Not measured yet. |
| Sales preparation and proposals | S0 | Not automated yet. |
The maturity assessment evaluates your processes against this model and shows where you stand and what blocks the next rung. It takes ten minutes.
Start the maturity assessment