AI Governance Hub

Free agentic AI control planner

Decide what an AI agent may do—and where a person must stop it.

Create a proportionate approval-gate and evidence plan for actions involving money, production systems, customer communication, sensitive data or safety. No prompts, identities, transaction details or business data are requested.

Create your approval plan · See worked examples · No signup required

Hard boundary: this planner cannot authorize, connect to or execute an agent action. A named accountable owner must verify the controls and approve any deployment.

1. Describe the proposed action

2. Which controls are evidenced today?

Select only controls that have been implemented and verified—not merely planned.

Worked example: a customer-support AI agent

These fictional scenarios show how changing one agent's authority changes its approval plan. Each example assumes every required control is evidenced, except the missing spend ceiling in Tier 4. For your own plan, check only controls that have been implemented and verified.

Tier 1 — review a draft

The agent drafts an internal answer in a sandbox. A responsible owner reviews the output before anyone relies on it.

Selections for this example

Advice or draft only · Fully reversible · Recommends only · Isolated sandbox. Required evidence: identity and sponsor, least privilege, audit log, emergency stop, evaluation and monitoring.

Tier 2 — approve a customer message

The agent stages a customer message in a queue; a person must approve before it is sent. The plan calls for an authorized approver and a recorded decision.

Selections for this example

External customer communication · Partly reversible · Can execute after approval · Limited production scope. Required evidence: the six draft controls, system-enforced approval and a tested compensating action. A sent message cannot simply be taken back.

Tier 3 — review a refund commitment

A refund action requires two independent approvers, a scope check and an atomic spend reservation. The exported plan lists the approval path and evidence to retain.

Selections for this example

Financial or procurement commitment · Partly reversible · Can execute after approval · Limited production scope. All ten listed controls are evidenced, including dual approval, the atomic ceiling and a tested compensating action.

Tier 4 — keep execution disabled

Use the same refund profile, but leave the atomic spend ceiling unchecked. The planner identifies that gap and recommends no delegation until required controls are closed and tested.

Selections for this example

Keep the Tier 3 selections and all other controls. Uncheck “Atomic spend or transaction ceiling enforced before action.” This changes the recommendation to “Tier 4 — do not delegate yet.”

Use your own bounded selections to generate an approval path, control gaps, evidence checklist and stop conditions, then download JSON or text. These examples do not execute an action or prove that a control works.

Put the plan into your governance review

These are separate tools; opening them does not transfer your plan or create an approval. Keep confidential evidence in your organization's approved systems.

Why approval gates matter

Agentic systems can plan and act across tools and data. Enterprise adoption depends on bounded authority, least privilege, traceable actions, reliable stop controls and explicit approval before high-impact or irreversible execution.

Frequently asked questions

Does this connect to an AI agent?

No. It runs locally and has no network connection or execution capability.

Does every agent action need the same approval?

No. Approval should reflect impact, reversibility, access and verified controls. High-impact or irreversible actions should not be treated like drafting advice.

Does a generated plan prove safety or compliance?

No. Technical implementation, control testing, legal applicability and accountable approval remain separate obligations.