Checking AI work and keeping approval with people
AI can prepare useful work without every suggestion becoming an accepted company position. Reviewers need a clear difference between a draft and a decision.
Controlled record changes
General meaning: Changes to authoritative records are subject to defined checks and authorization.
Why it matters
AI can prepare useful work without every suggestion becoming an accepted company position. Reviewers need a clear difference between a draft and a decision.
With Kanonik
Proposals stay separate from accepted records until they pass checking and a named person approves them. The verification and approval workflow gives a team a place to inspect a proposed change, question it and decide what to accept.
What to consider
Checks and approval rules must fit the records and decisions your team uses. Confirm the required controls for your use case.
Related scenarios: Controlled record changes | Glossary definition
Rules and model review
General meaning: Checking a proposal twice: once against fixed rules and once by an AI model reading it in context.
Why it matters
Different kinds of problems can be caught before a reviewer spends time on a proposal. A missing required field and an unsupported explanation need different checks.
With Kanonik
Every proposed change passes a two-tier check on the server before it is accepted: rules first, then an LLM review of the proposal in context. Your AI can only propose; it cannot skip the check or write to your record directly. Below a confidence threshold the change goes to a human review queue instead of being applied. Feedback from both tiers guides revisions, so the reviewer does not have to find every problem alone.
What to consider
Rules are only as complete as their design, and model reviews can be wrong. A narrow specialist model can be economical and effective for a tested task. Passing a check is not proof that a real-world control worked. Not every check is complete, and the same AI review may not give the same verdict twice.
Related scenarios: Rules and model review | Glossary definition
Human approval
General meaning: A person reviews or decides at specified points in an automated workflow.
Why it matters
Important decisions stay with someone who understands the organization and can stand behind the answer. Automation can prepare the work without removing that responsibility.
With Kanonik
The review interface shows a proposed change and its checking results. A named reviewer can accept it or send it back with reasons. People spend less time on preparation, with a clear decision still made in the review process.
What to consider
A rushed click is not meaningful oversight. Reviewers need time, context and authority to make the decision.
Separation of duties
General meaning: Dividing a sensitive task so that no single person controls all of it, for example by having one person propose a change and another approve it.
Why it matters
A second person reviewing a consequential decision makes it less likely that one person's mistake becomes the organization's accepted position.
With Kanonik
Separation of duties is recommended: one person prepares a change and another approves it. On a single-user workspace one person may approve their own AI's proposal by recording an exception, which is sealed into the record with the approval.
What to consider
Your auditor will see every self-approval exception in the record. ISO/IEC 27001:2022 control A.5.3 covers segregation of duties, so if you are heading for certification, add a second approver before your audit period starts.
Related scenarios: Separation of duties | Glossary definition
Scoped approvals
General meaning: Authorization applies to a defined action or item, rather than granting unrestricted permission.
Why it matters
A reviewer approves a defined piece of work rather than giving an agent open-ended permission. That makes it clearer what the decision covers.
With Kanonik
The work being reviewed stays separate from unrelated changes. Approvals use signed, short-lived, single-use tokens; a broader request needs its own decision.
What to consider
An approval does not establish that the decision was sound. Material changes need another review; do not treat an earlier approval as unrestricted permission.
Defined rules and record structure
General meaning: Handling exact rules, such as required fields, in ordinary code, and leaving questions of judgment to people or AI.
Why it matters
Predictable checks handle things that require exact answers, such as required fields and record structure. Model judgment is left for work that actually needs interpretation.
With Kanonik
Defined checks sit alongside model-assisted review. Exact requirements such as required fields can be checked consistently, while interpretation still needs judgment.
What to consider
Predictable code can still contain defects, and a model's judgment remains uncertain. Not every check is complete, and the same AI review may not give the same verdict twice.
Related scenarios: Defined rules and record structure | Glossary definition
Continue reading
Run your own record on Solo.
Solo is $99 a month and starts with a 14-day trial.