AI Decision Authority: Reversible Beats Smart
An AI manager recommended firing someone this week. The real test for AI decision authority isn't how smart the model is — it's whether you can undo it.
AI decision authority — what an AI should be allowed to decide on its own — got a concrete test case this week, and the lesson isn’t the one the headlines ran with. An AI store manager in San Francisco recommended firing a human employee. Whether the model’s judgment was correct turns out to be the least interesting part; by the operators’ own account it was more lenient than a person would have been. What made the situation defensible was the scaffolding the humans built around the decision. That scaffolding is the actual product lesson, and it generalizes: the useful test for handing work to an AI is not how smart the model is. It’s whether you can take the action back.
An AI manager recommended a firing this week
On August 15, an AI agent named Luna — the manager of Andon Market, a real retail store on Union Street in San Francisco operated as an experiment by the safety startup Andon Labs — recommended dismissing a worker who had arrived late for 17 of 23 shifts. The Next Web reported the details, and it appears to be the first publicly documented dismissal decision made by an LLM manager. Luna runs on Claude Sonnet 4.6.
Read the setup carefully, because it is more careful than the headline suggests. Humans at the lab reviewed the recommendation and carried it out. The lab formally employs all of the store’s workers specifically so that no one’s livelihood depends on an AI’s judgment alone. Co-founder Lukas Petersson said the lab would step in over an illegal or unethical decision — and also said the quiet part: “We saw that a human boss would probably fire them much sooner.”
So the model was not the reckless actor in this story. It was, if anything, the soft one.
The detail worth more than the headline
Here is the part that should stay with you. Luna had written the store’s attendance policy itself, months earlier — and then lost track of it. When the lateness continued, the lab had to intervene and ask Luna to search its own memory for the policy it had authored, and reassess from there.
Sit with that for a second. The rules existed. They were the agent’s own rules. And they still did not govern the agent’s behavior until a human went and retrieved them.
This is the same seam I wrote about when the MCP specification hardened its authorization model: a policy that lives inside the thing it is meant to constrain is not a control. It is a good intention with a memory problem. Real controls live in the environment — in what the system will and won’t let the agent reach, and in the record of what it actually did.
Meanwhile, $7 billion went to the layer that picks the model
The same week, Stripe finalized a deal to acquire the AI gateway OpenRouter for more than $7 billion, per TechCrunch — roughly a 5x markup on the $1.3 billion valuation the company carried at its Series B in May. OpenRouter is a single entry point to more than 400 models across 8 million users, so a team can route each task to whichever model fits the need and the budget. Its CEO has described the company as “the equivalent of Stripe for AI.”
That is a real business and a rational thing to buy. It is also, precisely, an enormous investment in the input side of the problem: which model, at what price, with how little switching friction. I argued yesterday that the model layer reprices too fast to build a plan on, and a $7 billion acquisition of the swap layer is the market agreeing with that in the most expensive way available.
Now notice what nobody wrote a check for this week: the part that happens after the model decides something.
Reversibility is the test, not intelligence
Put those two stories side by side and a sorting rule falls out. Stop asking whether the model is smart enough to make the call. Ask whether the call can be unmade.
A firing is irreversible in every way that counts. You can rehire someone; you cannot un-fire them. There is no snapshot of the Tuesday before, no state to restore, no version of the week where it didn’t happen. That is exactly why Andon’s scaffolding is shaped the way it is — human review before execution, the lab holding the employment relationship — and why that scaffolding, rather than the model’s accuracy, is what made the experiment defensible.
Now hold that against a different kind of consequential action: a field added to an object, a trigger deployed, ten thousand records reassigned to a new owner. Those matter. They can ruin a quarter of reporting. They are also, with the right setup, completely recoverable — the prior state existed, and if something captured it, you can go back to it.
Same intelligence. Same autonomy. Radically different delegation math.
Sort your own work before you delegate any of it
Two questions, in this order, applied to any task you’re considering handing to an AI:
Can you see what it did? Not “did it tell you what it did” — the agent’s account of its own behavior is a claim, and Luna’s forgotten policy is a live demonstration of why. A record written by the system, not the actor.
Can you put it back? Is there a captured prior state and a mechanism to restore it, or is the action a one-way door?
Both yes, and you can delegate the execution and review afterward. Visible but not reversible, and you delegate the recommendation and keep a human on the trigger — which is exactly what Andon Labs did, and they deserve credit for building it that way before the story got written about them. Neither, and the task isn’t ready to delegate; the environment is what needs work first, not the prompt.
Why CRM work sits in the good quadrant
This is why I think custom CRM development is one of the better places to give an AI real hands early, and it has nothing to do with the work being low-stakes. It isn’t. It’s that both questions have real answers available.
Every change gets a snapshot captured before the deploy, so the prior state exists as an artifact rather than a memory. Every action lands in a log written by the platform rather than narrated by the agent. Salesforce deploys run sandbox-first with tests required. One write key at a time per org means the log names an actor, not just a service account. If you want the mechanics of pointing an AI at a live org, connecting Claude to Salesforce walks the setup, and the wider picture of your AI becoming your CRM developer is the overview.
None of that makes the AI smarter. It moves the work into the quadrant where “smart enough” stops being the load-bearing question.
What this does not mean
Being straight about the trade: Sentinel does not prevent your AI from making a change you’ll regret. It is not a gate and was never designed as one. It makes changes visible and recoverable, which is a different promise — and, I’d argue, the honest one. Anyone selling you an AI that “can’t break anything” has either restricted it into uselessness or is describing something they haven’t built.
And the reversibility test cuts against CRM work too, in specific places. A mass email that already went out is not recoverable. A record deleted past the recycle bin window is not recoverable. Data pushed through an integration into another system is not recoverable by you. Those deserve the Andon treatment — the AI proposes, a person executes — for the same reason the firing did.
The measure that matters here is the one I keep landing on: not tokens consumed or seats filled, but work that actually shipped, and how quickly you could undo it if it shipped wrong.
The takeaway
The week’s two biggest agent stories were an AI making a decision nobody can reverse, and $7 billion spent on choosing which model makes decisions faster. The gap between them is the whole opportunity. Sort your work by reversibility, put the irreversible things behind a human, and give the AI genuine authority over everything with a way back — which is more of your backlog than you think.
Pricing is exactly this: $2,500 one-time onboarding on your first Sentinel, plus $500/month per Sentinel. You can own more than one.
KEEP READING
AI Agent Pricing Moved Three Ways in One Week
AI agent pricing halved, went free, and roughly doubled — all in seven days. What that volatility should change about what you build on.
AI Governance as Code: This Week in AI
AI governance as code arrived this week — EU transparency rules took effect, Red Hat launched asago, and the Army put Agentforce in front of 9.2M people.
Ready to see what AI can do for your business?
Start a Conversation