Let an action's consequences determine the control it needs. Suggesting a headline needs different protection from sending a price to a customer or changing payment details. General permission to use AI does not specify which of those actions are allowed.

Start with a list of concrete actions. Describe the information and permissions each one needs.

Approval must refer to a specific action

Show the recipient, proposed change and evidence behind it. A person reviewing an email needs to read the exact email. A person approving an update needs to see which field changes and its previous value.

If the evidence or proposed action changes after approval, the system needs to assess whether the decision still applies. A general button labelled Continue provides little support for that judgement.

An illustrative decision checklist

The checklist is a working proposal. The same action may need stricter controls depending on the industry, information and agreements involved. Legal requirements need a separate assessment.

  • Read approved internal material: restrict access and log relevant use.
  • Create an internal draft: allow it within the task and mark what needs checking.
  • Send information to a customer: review the recipient, content and any commitments.
  • Change business-critical information: use a designated authorised reviewer and a controlled transfer.
  • Handle unclear instructions or missing evidence: stop and ask for a decision.

Permissions still apply when an instruction is misunderstood

An instruction never to send email does not remove the ability to send it. Restrict tools and accounts to what the task requires. A read-only pilot normally does not need an administrator's full permissions.

For material from emails, documents or websites, distinguish task evidence from instructions about permitted actions. A document must not be able to give an agent new authority.

Give the reviewer time and a way to stop

If hundreds of similar suggestions require clicks without context, approval can become a habit. Provide the information needed for the decision and make exceptions visible. Decide who takes over when the usual reviewer is unavailable.

Test a rejected suggestion and a case that gets stuck. The system needs to stop without pretending the task is complete, and without automatically asking other people until someone says yes.