Free agentic AI control planner
Decide what an AI agent may do—and where a person must stop it.
Create a proportionate approval-gate and evidence plan for actions involving money, production systems, customer communication, sensitive data or safety. No prompts, identities, transaction details or business data are requested.
Create your approval plan · See worked examples · No signup required
1. Describe the proposed action
Planning outcome
Approval tier
Control gaps to close
Evidence to retain
Stop conditions
Planning aid only. Not legal advice, security certification, compliance determination or evidence that a control operates effectively.
Worked example: a customer-support AI agent
These fictional scenarios show how changing one agent's authority changes its approval plan. Each example assumes every required control is evidenced, except the missing spend ceiling in Tier 4. For your own plan, check only controls that have been implemented and verified.
Tier 1 — review a draft
The agent drafts an internal answer in a sandbox. A responsible owner reviews the output before anyone relies on it.
Selections for this example
Advice or draft only · Fully reversible · Recommends only · Isolated sandbox. Required evidence: identity and sponsor, least privilege, audit log, emergency stop, evaluation and monitoring.
Tier 2 — approve a customer message
The agent stages a customer message in a queue; a person must approve before it is sent. The plan calls for an authorized approver and a recorded decision.
Selections for this example
External customer communication · Partly reversible · Can execute after approval · Limited production scope. Required evidence: the six draft controls, system-enforced approval and a tested compensating action. A sent message cannot simply be taken back.
Tier 3 — review a refund commitment
A refund action requires two independent approvers, a scope check and an atomic spend reservation. The exported plan lists the approval path and evidence to retain.
Selections for this example
Financial or procurement commitment · Partly reversible · Can execute after approval · Limited production scope. All ten listed controls are evidenced, including dual approval, the atomic ceiling and a tested compensating action.
Tier 4 — keep execution disabled
Use the same refund profile, but leave the atomic spend ceiling unchecked. The planner identifies that gap and recommends no delegation until required controls are closed and tested.
Selections for this example
Keep the Tier 3 selections and all other controls. Uncheck “Atomic spend or transaction ceiling enforced before action.” This changes the recommendation to “Tier 4 — do not delegate yet.”
Use your own bounded selections to generate an approval path, control gaps, evidence checklist and stop conditions, then download JSON or text. These examples do not execute an action or prove that a control works.
Put the plan into your governance review
- Record the accountable decision — document the role, evidence references, conditions and next review date after human review.
- Prepare an AI incident response plan — map ownership, evidence preservation and human review if a stop condition is triggered.
- Review the AI risk register template — see how risks, ownership and follow-up actions can be organized.
These are separate tools; opening them does not transfer your plan or create an approval. Keep confidential evidence in your organization's approved systems.
Why approval gates matter
Agentic systems can plan and act across tools and data. Enterprise adoption depends on bounded authority, least privilege, traceable actions, reliable stop controls and explicit approval before high-impact or irreversible execution.
Frequently asked questions
Does this connect to an AI agent?
No. It runs locally and has no network connection or execution capability.
Does every agent action need the same approval?
No. Approval should reflect impact, reversibility, access and verified controls. High-impact or irreversible actions should not be treated like drafting advice.
Does a generated plan prove safety or compliance?
No. Technical implementation, control testing, legal applicability and accountable approval remain separate obligations.