For most of last year, Vetch had a single global "autonomy" slider — Off, Ask, Auto. It was wrong, but in a useful way. The wrongness taught us that autonomy isn't a global property; it's a property of capability × shift × clinic.
The three modes
- Suggest — Vetch offers a recommendation; nothing happens until a human acts.
- Ask — Vetch prepares the action and asks for one tap of confirmation.
- Auto — Vetch acts; humans review the audit log if they want to.
Why three, not two
A binary "Vetch can / cannot" is too coarse. The interesting cases live in the middle: tasks that are safe enough to act on but high-volume enough that you don't want to confirm individually (Ask aggregated). Tasks that are sensitive but low-volume enough that one-tap is fine (Ask per item).
Per capability, per shift
We expect most clinics to run charting on Auto during business hours and Suggest at 2am — not because Vetch is worse at 2am, but because the ER vet doesn't want a chart auto-finalizing while she's still typing dose calculations. The model doesn't change; the threshold for committing does.
These are starting points, not commandments. Most clinics tune them within the first 30 days.
What we threw out
We had a fourth mode for a while called "Pilot." The idea was a sandboxed dry-run where Vetch would tell you what it would have done. Nobody used it. Reading what Vetch would have done is more cognitive load than reviewing what Vetch did, because the action exists in your imagination instead of as a thing you can accept or revert. Killed it after two months.