AI Decision Rights Map

Three rules in under a minute: two gaps found, one fixed with a click, and the go-live blockers that are still open.

An AI decision rights map is an approval matrix for AI agents. It lists every action the AI can take and gives each one of four modes: act alone, draft for a person to approve, recommend only, or never. Per action it also records the condition, the named approver and whether the approval is checked again when the action runs.

The four modes

ModeWhat the AI doesTypical actions
Act aloneExecutes without a person, inside a written limitSorting requests, tagging tickets, small refunds
Draft, a human approvesPrepares the action, a named person releases itCustomer replies, payments above a limit, master data changes
Recommend onlySuggests, a person decides and executesDiscounts, supplier choice, write-offs
NeverThe action is not available to the AIDeleting customer records, changing permissions

In the usual oversight terms, “act alone” is autonomous, “draft” is human-in-the-loop with approval before the action, “recommend” leaves the decision with a person, and “never” is a hard stop.

Six gaps the map flags

  1. Moves money with nobody approving. An “act alone” rule on refunds, payments, credit notes or discounts. Fine if intended, as long as the limit is written down.
  2. Cannot be undone, nobody approves. Deleting, sending, publishing, signing or transferring without an approver.
  3. Reaches customers with nobody approving. Replies, offers or posts that go out on their own.
  4. Needs approval, but nobody is named. “A human approves” without a role means anyone who sees the request can approve it.
  5. Approval not re-checked when the AI acts. A stale approval: given on Monday, still counted on Wednesday, even if the approver has left or the amount has changed.
  6. Contradicts another rule. The same action with two modes and no condition that tells them apart.

The gaps come from fixed rules applied to the table, not from a model: the same table always shows the same gaps.

Three go-live blockers

Before an AI runs unattended, three operating facts decide whether the rules hold:

  • Weekend on-call. If nobody is reachable, every “act alone” rule drops to “draft” at weekends.
  • Stop rule. A threshold that pauses the AI, for example when more than 3% of its decisions get reversed.
  • Named owner. One person updates the rules when an approver leaves or a limit changes.

Example: an AI in customer service

ActionAI mayOnly ifApproverChecked again when it runs
Sort incoming requestsact alone–––
Reject requestsnever–––
Issue refundsact aloneunder $100, unless the customer had one before––
Issue refundsdraft, a human approvesabove $100Financeno
Change SAP master datadraft, a human approves–not namedno

Three gaps: refunds move money with nobody approving, the Finance approval is not re-checked when the refund is paid out, and nobody is named for SAP master data. The tool above starts with this table.

Where the map fits

It is the page to agree on before a pilot, with finance, IT security and the works council at the table. For high-risk systems the EU AI Act requires that people can oversee the system effectively (Article 14) and that deployers assign that oversight to people with the competence and authority to exercise it (Article 26). The OWASP Top 10 for LLM applications lists excessive agency (LLM06) as a risk of its own: more functions, permissions or autonomy than the task needs. The map does not make a system compliant. It documents who decides what, so the pilot can enforce it.

The approval flow itself is in the human-in-the-loop approval blueprint. Which memory writes never need a person is in agent memory approval gates. The step before, which kind of AI fits at all, is the AI Solution Shape, and all free tools are on one page. If the map shows open blockers, the AI Pilot → Production Audit closes them in writing.

Frequently asked questions

What is an AI decision rights map?

A table that lists every action an AI system can take and says, per action, whether it may act alone, only draft for a person to approve, only recommend, or never act. It also records the condition, the named approver and whether the approval is checked again when the action runs.

Does every AI action need human approval?

No. Reversible, internal actions of low value can run on their own inside a written limit. Actions that move money, reach customers or cannot be undone need a named approver until the logs show that more autonomy is safe.

What is a stale approval?

An approval that still counts after the facts behind it changed: the approver left, the amount grew, the customer withdrew. The fix is to check the approval again at the moment the AI executes the action.

How is this different from human-in-the-loop?

Human-in-the-loop says that a person is involved somewhere. The map says where: which action, which person, under which condition, and whether that person's approval still counts when the action runs.

Is my data uploaded?

No. The table is built and checked in your browser. It is stored only if you create a share link, and then for 90 days. The PDF is generated on your device.

Does the map make an AI system compliant with the EU AI Act?

No tool does that on its own. The map documents one part of human oversight: which people oversee which actions. For high-risk systems, Article 14 requires that oversight is possible and Article 26 requires deployers to assign it to people with the competence and authority to exercise it.

The context layer for your AI agents

Your agents answer from whatever the retriever finds, and too often that is last quarter's truth. I build the context layer they answer and act from: a temporal knowledge graph that keeps every fact with its source and the time it held, reads with each person's own permissions, and writes nothing without a person's approval. On your own tenant, billed by the hour, step by step.