Classify each action by impact

Reading and summarizing are lower risk than sending email, changing a deal stage, approving a customer, moving money, or deleting a record. Map every tool to a permission level.

Show evidence with the recommendation

A reviewer should see the source fields, policy excerpts, and uncertainty that produced the recommendation. A polished answer without evidence encourages rubber-stamping.

Use explicit approval states

Draft, pending approval, approved, executed, failed, and reversed should be distinct states. The interface must not imply that an action happened when only a draft exists.

Log who approved what

Record the user, timestamp, relevant inputs, model and prompt version, proposed action, approval, and execution result. Avoid logging sensitive data that the audit does not need.

Fail safely

If a source is missing, a tool times out, or the model is uncertain, pause and route to a person. Do not guess a financial term, approval, deadline, or compliance answer.