The problem
Without a gate, one bad draft reaches a customer before anyone sees it, and trust in the whole system goes with it. With a gate that never loosens, the reviewer becomes the bottleneck and people start approving without reading.
How to run it
- Split reads from writes
List every action each agent can take. Reads run freely, and every write (send, post, pay, change a record) becomes a proposal that waits in a queue.
- Put the evidence on the card
Each proposal shows the draft, the facts it used with links to their source, and approve, edit and reject in one click. Nothing is written until the person confirms.
- Commit exactly once
Claim the approval inside a database transaction, so a double click or a retried request fires the effect one time. A rejected proposal never changes state.
- Start every write on approve to send
Give each action type a rung: draft only, approve to send, auto after 24 hours unless cancelled, or autonomous. No write agent starts autonomous.
- Demote fast, promote on purpose
Two consecutive rejects step that action type down one rung. Approvals never promote on their own; moving up is a decision the owner makes and logs.
- Keep some actions off the ladder
Name the actions that always need a person however well the agent does, such as clearing a conflict of interest or giving advice that needs a license.
Done when
- no code path lets an agent write, send or pay without a committed proposal.
- a double click and a replayed request on one approval each produce exactly one effect, proven by a test.
- every action type has a recorded rung, and a test shows two consecutive rejects demote it.
- each proposal card links every figure in the draft to the record it came from.
How teams get it wrong
- Teams gate the whole agent instead of each action type, so one risky action keeps every safe one stuck in review; give each action type its own rung.
- The approve click and the send run as two separate steps, so a retry sends twice; claim the decision and fire the effect in one transaction.
- Approvals quietly promote the agent until it runs unattended; make every promotion a logged decision by the owner.
# Agent approval register Agent: ____ Approver (named person): ____ Review queue lives in: ____ Date set up: ____ ## Action types | Action | Read or write | Starting rung | Always needs a person | Sources shown on the card | |---|---|---|---|---| | ____ | ____ | approve to send | yes / no | ____ | | ____ | ____ | approve to send | yes / no | ____ | | ____ | ____ | draft only | yes / no | ____ | Rungs: draft only, approve to send, auto after 24 hours unless cancelled, autonomous. ## Rules - Demote one rung after ____ consecutive rejects (default 2). - Promote only when the unedited approval rate holds above ____% for ____ days. Log who decided. - Actions that never leave approve to send: ____ ## The proposal card shows - [ ] The full draft, editable - [ ] Every figure linked to its source record - [ ] Approve, edit and reject in one click - [ ] One line on why the agent proposed it ## Tests before launch - [ ] A double click on approve fires the effect once - [ ] A replayed approval request fires the effect once - [ ] A rejected proposal changes nothing - [ ] Two rejects in a row demote the rung ## Promotion log | Date | Action | From rung | To rung | Decided by | Evidence | |---|---|---|---|---|---| | ____ | ____ | ____ | ____ | ____ | ____ |