Navigator Framework™ · Agents drive. Humans navigate. · v0.1 working draft · 2026

The governance standard for Governable Autonomy.

How much autonomous decision-making can your organisation safely delegate to AI — and can you prove it? Five capabilities. Five stages of autonomy, from Traditional to Continuous Assurance. A formula that distinguishes a Certified Stage, evidenced by an assessor, from an Indicative Stage, a self-reported estimate. AI systems are not valuable because they are autonomous. They are valuable because they remain governable.

5
Capabilities
0–4
Stages of autonomy
33
Controls, NAV–1 through NAV–G
4
Risk classes
5
Documents in the family
v0.1
Working draft · 2026
Start here

Start with the question
you are trying to answer.

The Navigator family is five documents, each answering one question in the chain from concept to implementation. Start wherever your question is.

01
Board · Commissioning Leadership · First-time Readers
What is Governable Autonomy, and why does it matter?
The Navigator Primer Defines the concept, one page
02
Navigator Assessors · Commissioning Leadership
How is Governable Autonomy actually measured?
The Assessment Guide Measures it
03
Harness Owners · Governance Functions
What controls actually have to exist, and which are non-negotiable?
The Controls Catalogue Implements it
04
Risk, Compliance & Charter Approvers
What applies, and how strictly, at each risk class?
The Critical Controls Guide Governs it by risk class
05
Implementation Teams · First-time Adopters
What does all of it look like, put together?
The Reference Architecture Shows it, worked

Not sure where you stand?

Take the Navigator Maturity Diagnostic →
I. The premise

The question every AI initiative eventually faces.

How much autonomous decision-making can your organisation safely delegate to AI — and can you prove it? Most organisations answer the first half instinctively and skip the second. The Navigator Framework™ exists to make both halves answerable, in the same terms, by the same evidence.

Autonomy moves through five stages, from a human authoring and reviewing every output to AI operating within approved objectives under continuous, evidenced audit. The pivotal step is the move from supervised loops to governed autonomy — where oversight stops reviewing every output and becomes authoritative only at the moment it is needed.

The operating principle

Agents drive. Humans navigate.

AI systems are not valuable because they are autonomous. They are valuable because they remain governable. The framework does not certify capability alone — it certifies the minimum of what a system is capable of, what its risk permits, and what can actually be evidenced. Capability never overrides the risk ceiling.

II. The five capabilities

Five capabilities. Scored 0–4, every one.

The Navigator Capability Model assesses five capabilities, each on its own 0–4 evolution scale, each with the same nine-part structure: purpose, required skills, engineering artefacts, observable evidence, assessment criteria, and common anti-patterns. A system's Capable Stage is the minimum of its Required capability scores — not the average.

Capability 01

Human Responsibility.

Holds when

A named human owns every autonomous decision the system makes.

Fails when

Autonomy without a responsible human is not governance, it is abdication.

Capability 02

Decision Governance.

Holds when

Escalation triggers are hard stops the harness actually enforces.

Fails when

An advisory trigger is not an oversight architecture. It is logging with aspirations.

Capability 03

Engineering Capability.

Holds when

The harness technically enforces the governance design, sandbox, checkpoints, kill switch.

Fails when

Governance design with no engineering counterpart is fiction — the appearance of protection, which is worse than none.

Capability 04

Knowledge Capability.

Holds when

What the system reasons from is sourced, current, and governed.

Fails when

A system can have excellent execution controls and still make confidently wrong decisions if what it reasons from is stale or unsourced.

Capability 05

Assurance Capability.

Holds when

Claims of control are backed by evidence an assessor can independently verify.

Fails when

This is the capability that turns a design into a fact — without it, every other capability is a claim, not a certification.

The Certified Stage formula: Certified Stage = min(Actual Stage, Capable Stage, Risk Ceiling, Evidence-Supported Stage). If evidence is self-reported rather than assessor-verified, no Certified Stage is computed — only an explicitly labeled Indicative Stage. Four diagnostic findings follow from the gap between them: Governance Failure (operating beyond the risk ceiling), Assurance Failure (claiming controls that cannot be demonstrated), Competitiveness Finding (unnecessary overhead below what capability and risk permit), or Aligned.
III. The family & the five stages

Five documents. Five stages of autonomy.

The Navigator family is five documents, each tracing back to a control, a gate, or a determinant defined in the one before it. Together they answer: what is Governable Autonomy, how is it measured, how is it implemented, how strictly by risk class, and what does it look like put together.

Document 01 · Defines it
The Navigator Primer

Governable Autonomy.

Download PDF ↓

The concept layer, on one page. Defines Governable Autonomy, the five capabilities assessed at every stage, and the five-stage evolution model that runs from Traditional (AI absent from the decision) to Continuous Assurance (AI operates within approved objectives, governed by ongoing telemetry and periodic, evidenced audit).

What it establishes
  • ·Five capabilities — Human Responsibility, Decision Governance, Engineering, Knowledge, Assurance
  • ·Five stages, 0 through 4, and the pivotal step from review to authoritative escalation
  • ·The risk ceiling — capability never overrides what risk permits
Document 02 · Measures it
The Assessment Guide

How Governable Autonomy is measured.

Download PDF ↓

The scoring instrument. Specifies the Certified Stage formula, the four diagnostic findings, capability applicability by system archetype, and the Autonomy Contract template every assessment produces. Its core discipline is preventing overclaiming — distinguishing an assessor-evidenced Certified Stage from a self-reported Indicative Stage.

What it establishes
  • ·Certified Stage = min(Actual, Capable, Risk Ceiling, Evidence-Supported)
  • ·Four findings — Governance Failure, Assurance Failure, Competitiveness Finding, Aligned
  • ·The Autonomy Contract — the per-system operational artefact every assessment produces
Document 03 · Implements it
The Controls Catalogue

How governance is implemented.

Download PDF ↓

The implementation layer. 33 numbered controls (NAV-1.x through NAV-G.x) across the four stages, split into Hard controls (binary, no relaxation by size or risk) and Graduated controls (formality and cadence scale with risk class, but never whether the control exists). Defines the actual gate criteria for advancing between stages.

What it establishes
  • ·8 controls that are always Hard — sandbox, kill switch, tested, ledger, traceability, risk ceiling
  • ·Stage gates 0→1, 1→2, 2→3 (the critical gate), 3→4 (design spec)
  • ·The Governance Operating Model — recertification, reporting, framework evolution
Document 04 · Governs it by risk
The Critical Controls Guide

What applies, and how strictly, by risk class.

Download PDF ↓

Organised by risk class, not by control, because that is how the question actually arrives in practice. Walks through the five risk-classification determinants and what each of the four risk classes — Low, Moderate, High, Critical — requires. For Critical-class systems, Level 2 is the destination, not a waypoint; any roadmap implying eventual Level 3 is itself a governance finding.

What it establishes
  • ·Five determinants — reversibility, named accountability, explainability, regulatory class, blast radius
  • ·Requirement tables at Low, Moderate, High, and Critical for every control group
  • ·Sign-off authority by risk class — from engineering leadership to board-level exception approval
Document 05 · Shows it, worked
The Reference Architecture

What it looks like, put together.

Download PDF ↓

The only document in the family that introduces no new rules — patterns and worked examples instead. A reference harness architecture (orchestration, sandbox, trigger engine, telemetry, authority ledger, kill switch), patterns by system archetype, and an eighteen-month worked example taking a customer-facing loan-inquiry assistant from Level 1 to a certified Level 3.

What it establishes
  • ·The five components a Level 2+ harness needs, regardless of vendor
  • ·Patterns for four common archetypes, each with its typical failure point
  • ·Common implementation pitfalls across engagements — what to watch for first
→ Navigator Lite for teams of 2–15
Five stages of autonomy · oversight changes shape as autonomy increases
Stage 0
Traditional
Human-authored, human-reviewed
Stage 1
Assisted
AI assists, human reviews every output
Stage 2
Supervised Loops
Bounded tasks, mandatory checkpoints
Stage 3
Governed Autonomy
End-to-end, escalation not per-output
Stage 4
Continuous Assurance
Governed via telemetry & evidenced audit
The pivotal step is 2 → 3, where oversight moves from reviewing every output to being authoritative at the moment it's needed. Stage 4 is a design direction, not yet an observed operating reality.
IV. How organisations use it

Three ways to work with the Navigator Framework™.

Way 01

As an internal standard.

Adopt the Navigator Framework™ internally — classify your systems into risk classes, build the harness the Reference Architecture describes, and hold the operating history each stage gate requires before advancing. The framework is a working draft, published for early input: no licence fee, no onboarding required. Download the family and begin.

Download the Navigator family →
Way 02

As an audit target.

Engage Orquestra AI to run an independent Navigator Audit — an assessment of your AI systems against the five capabilities, scored against the Certified Stage formula, and classified against the four risk classes. You receive an Autonomy Contract per system, a diagnostic finding, and a board-ready assurance summary.

Request a Navigator Audit →
Way 03

As a training curriculum.

The Navigator Framework™ is the basis of Orquestra's training and capability building programmes — the Navigator Capability Model for governance functions, classification workshops for charter approvers, and harness-architecture sessions for engineering leadership.

Book a training session →
V. The framework in numbers

Built to be measurable.

Every control in the Navigator Framework™ carries an ID, a Hard-or-Graduated classification, and a stage it belongs to. Every stage gate has named evidence requirements. Governance that cannot be measured cannot be defended.

5
Capabilities scored 0–4 — Human Responsibility, Decision Governance, Engineering, Knowledge, Assurance.
5
Stages of autonomy, 0 Traditional through 4 Continuous Assurance.
33
Numbered controls, NAV-1.x through NAV-G.x, split Hard versus Graduated.
8
Controls that are always Hard — no relaxation by risk class, size, or maturity.
4
Risk classes — Low, Moderate, High, Critical — that scale cadence and evidence rigor.
v0.1
Working draft status — every gate criterion and threshold is Stable or explicitly Provisional.

Every one of those controls is catalogued: what it requires, who owns it, what evidence satisfies it, and the acceptance criterion an assessor uses to verify it. See the Controls Catalogue & Critical Controls Guide →

VI. Authorship & open adoption

Created by Orquestra AI. Open for adoption.

About the Navigator Framework™

The governance standard born from the trust gap.

The Navigator Framework™ was created by Orquestra AI in 2025–2026 in response to a specific structural gap: AI systems generating work faster than human assurance processes could verify it. Organisations were shipping code they believed had been reviewed when it had not. Decisions were being attributed to AI agents that no named human could defend.

The framework was designed to close that gap — not by slowing AI down, but by placing named human judgment at the boundaries where verification would otherwise be skipped. The standard it targets is not certainty. It is reasonable assurance — the same standard financial audit applies.

The current family is a v0.1 working draft, published for early input rather than a finished standard. Every claim in it is labeled Stable or Provisional so readers know which figures are settled and which are still being piloted. We audit against it, we're building the pilots that will move Provisional figures to Stable, and we publish the working drafts so any organisation can follow along.

Version 0.1 · Working draft · 2026 Not yet released for general adoption Five documents published Trademark application in preparation
How to reference: "Navigator Framework™, Orquestra AI, v0.1 working draft, 2026. orquestraai.io/navigator" — or cite the relevant document directly. Status: working draft, shared for early input; trademark application in preparation, not yet registered.
VII. The family & downloads

Take the framework off the page.

All five documents are open distribution — working drafts, shared for early input. No email gate. Download and share freely with assessors, governance functions, and commissioning leadership.

Adopt the framework. Or audit against it.

The Navigator Framework™ is a working draft, open for early adopters. Download the family and implement it internally — or engage Orquestra AI to run an independent Navigator Audit and produce the Autonomy Contract and evidence package your board and regulators need.