{"id": "TTC-105", "slug": "human-decisions-and-approval", "title": "Human decisions and approval", "level": "beginner", "summary": "Drafting, recommending, approving, and executing are different states; an AI output must never be treated as permission for a real action unless the authorized human explicitly approves that action.", "learning_outcome": "Map a workflow into draft, recommendation, approval, and execution states with a named owner and bounded approval.", "explanation": "Design the handoff before generating the draft. Name the person or role accountable for the decision, the evidence they receive, and the exact action their approval covers. Approval of wording is not approval to publish, and approval of one transaction is not standing authority for later transactions. Make pause and escalation visible success states. High-impact decisions need enough time, alternatives, uncertainty, and appeal or correction paths for meaningful oversight. Keep an audit record of proposal, reviewer, decision, scope, time, and execution result.", "worked_example": "Fictional case: an assistant drafts a refund note for Northwind Bicycles. It may calculate the proposed amount from synthetic policy data, but labels the result DRAFT. A service manager approves the amount and message separately. Only the approved one-time instruction may be sent by the authorized system.", "exercise": "Choose a fictional workflow containing a real-world effect. Draw its states and transitions. For each transition, name the actor, evidence, allowed action, expiry, and rejection route. Test one case where a draft is approved for review but not for execution.", "success_criteria": ["No external effect can occur from a draft-only state.", "Each approval identifies actor, object, scope, time or expiry, and the action it permits.", "Rejection, uncertainty, and escalation leave an observable record and do not silently advance the workflow."], "limitations": ["Human review can become a rubber stamp if the reviewer lacks time, evidence, competence, or real ability to refuse.", "An approval record demonstrates a process step, not that the underlying decision was correct or lawful."], "prerequisites": ["TTC-101", "TTC-104"], "next_lessons": ["TTC-108", "TTC-115", "TTC-119"], "copyable_material": "# TTC-105 \u2014 Human decisions and approval\nObjective: Keep advice and drafts separate from authority to create an external effect.\nProcedure: Define states, named owners, required evidence, approval scope, expiry, rejection, and execution receipt.\nRequired evidence: Retain the proposal, reviewer decision, authorized scope, and actual result as separate records.\nBoundaries: Approval never expands beyond the named object and action; publishing, sending, spending, and access require explicit authority.\nCompletion test: A draft cannot reach execution without the correct reviewer and an auditable bounded approval.\nReview rule: Treat generated work as a draft until the named human reviewer accepts it.", "sources": [{"title": "Regulation (EU) 2024/1689 (Artificial Intelligence Act)", "publisher": "European Union", "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj"}, {"title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0)", "publisher": "National Institute of Standards and Technology", "url": "https://www.nist.gov/itl/ai-risk-management-framework"}], "version": "1.0.0", "reviewed_on": "2026-10-03", "review_status": "reviewed", "next_review_criteria": "Applicable human-oversight requirements or the product's approval-state model changes.; A cited primary source is materially revised, replaced, or becomes unavailable.; Repeated learner results show that the exercise or success criteria are ambiguous.", "canonical_aliases": [], "canonical_url": "https://teachthecompany.com/school/human-decisions-and-approval/"}