Most organizations don't worry about AI being smart enough. They worry about it doing something nobody approved: sending an email to a client, changing a record, or stating something that isn't true. The fix is not to avoid AI. It is to decide, up front, where AI stops and a person takes over.
A simple rule works well in practice: AI helps, people decide. Here is how to turn that rule into system design.
Start by sorting actions, not models
Before choosing a model or a tool, list the actions the system could take. Then sort each action into one of three groups.
- AI can do it alone. Searching documents, summarizing, drafting, comparing a draft to a checklist, flagging missing information. These are reversible and stay inside the team.
- AI drafts, a person approves. Anything that leaves the organization (emails, proposals, published content), changes a record (customer data, HR or financial entries), or commits money or time.
- People only. Decisions with legal or strategic weight: whether to bid, what price to quote, what to sign.
This list becomes the design. If an action is in the second group, the system must physically route it to an approval step. It should not rely on a prompt that asks the model to be careful.
Make the gate part of the software, not the prompt
A prompt such as "don't send emails without approval" is a suggestion. A gate is a hard control:
- The tool simply isn't there. An assistant that drafts emails gets a "create draft" tool, not a "send" tool. Sending happens in a separate step that only a person can trigger.
- Approvals are named. Each action type has an owner, for example the sales lead for client emails or the proposal manager for proposal sections. "Someone on the team" is not an approver.
- Every step is logged. Record what the AI was asked, which sources it used, what it produced, who approved it and what changed. When something goes wrong, the log tells you where.
Show the sources
People can only approve what they can check. Every answer or draft should cite where its facts came from: the policy, the contract clause, the earlier proposal. If an assistant can't point to a source, the reviewer should treat the statement as unverified.
This matters even more for content about the organization itself. AI should never invent experience, certifications, prices or results. A useful pattern is to keep a short register of approved company facts and allow drafting tools to use only those.
Respect permissions at retrieval time
An internal assistant that searches company documents must follow the same access rules as the people using it. If an employee can't open the HR folder, the assistant shouldn't quote from it when that employee asks a question. The permission check belongs inside the search itself, before any text reaches the model.
Keep the review fast
Approval gates fail when they become a bottleneck and people start working around them. A few habits keep them usable:
- Show the reviewer the draft, the sources and the proposed action on one screen.
- Allow quick edits, not just approve or reject.
- Batch low-risk approvals; keep high-risk ones individual.
- Measure how long items wait for approval, and fix the slow spots.
Where to start
Pick one process with a lot of routine work and clear rules, such as answering common customer questions from your own documentation or preparing first drafts of standard documents. Map the actions into the three groups above, build the gate, and run it for a few weeks before expanding.
If you are planning an AI project and want approval gates designed in from day one, talk to our team.
