Anything permanent waits, assigned to a human.
An AI agent can do plenty on its own. What it cannot do is anything you could not take back: deploying, publishing, sending something to your customer. Those stop before they happen and are assigned to a human, who says yes or no in writing.

Stopped before it ran, and assigned to a named human.
Decided in advance, by rules a human assigned
When a human assigns a playbook to a project, its rules travel with the work: which checks have to pass, and how reversible an action has to be before an AI agent may take it alone. What a playbook does not decide is how risky an action is. That is sorted in advance into one of three kinds, and an AI agent does not get to say which one its own request is. Deploying, merging, publishing, sending something to a customer and changing how data is stored are permanent wherever they run, and a playbook can raise that bar but never lower it.
- Read-only: it happens, nothing changes.
- Reversible: it happens now and goes on the record, because putting it back is possible.
- Permanent: it does not run when it is called. It is proposed, assigned to a human, and that human approves or refuses it.
What the AI agent gets back is a ticket, not a result
When an AI agent asks for something permanent, the request is stored word for word and it gets a reference number instead of a result. It can wait on that number; it cannot hurry it. Every request also needs a real reason, and a placeholder like test or n/a is refused.
A human approves the actual request
The reviewer sees which kind of action it is, the reason, who asked and on whose behalf, and the request itself written out exactly as it will run. Approving needs a typed reason. So does rejecting. Both go on the record, assigned to the reviewer who made them, with the time.

An AI agent can never be the approver
A machine sign-in cannot approve, even one acting for a human. Only a signed-in human can. A decision is also safe to click twice: a lost response and a second click cannot fire a permanent action twice.
Requests nobody looks at do not quietly vanish
A request left for seven days expires, and the queue says so. The three figures on the page, how many are waiting, how many were decided, and how long a decision takes, are counted from the record. Letting things sit cannot make them look better.
What an approval costs you
Time. Somebody has to read the request and decide, and until they do, the work is stopped. That is the trade this page is asking you to make, and it is worth making only for the actions you could not take back.
See the queue with your own actions in it.
Also in Governance
- Audit trail and evidenceWho did what, on a sealed record, exported when someone asks.Read the page
- AI agent securityA name, a limit, and somebody who can stop it.Read the page
- AI agent identityA human lets an AI agent in, and can stop it again.Read the page
- What an AI agent may doIt never reaches further than the human it works for.Read the page
- AI agent sign-insA sign-in expires sooner the more it can do.Read the page
- Approved modelsWhich models may run, who approved each one, and what it left behind.Read the page
- Scans and approved packagesApproved packages at the exact version, checked when used.Read the page