ПостАгенты, безопасность и доверие

Every approval step is a claim that a person could have stopped it.

A screen showing a summary and two buttons has added latency, not oversight — and the proposal on screen has to be the proposal that executes.

Lukman Nuriakhmetov
Lukman Nuriakhmetov
1 мин чтения · 12 августа 2026 г.

Every approval step in an agent workflow is a claim that a person could have stopped it.

The screen decides whether that claim is true.

Most approval surfaces show a generated summary and two buttons. To actually decide, a reviewer needs more: the exact action, the state it will change, what authority it runs under, the evidence behind it, where the agent was uncertain, what the alternatives were, and how reversible it is once approved.

A screen that hides those has not added oversight. It has added latency — a person in the path who cannot meaningfully refuse.

There is a second failure underneath it. The proposal on screen has to be the proposal that executes. If the agent re-plans after approval, or the underlying state moves between the click and the action, the reviewer approved something that no longer exists. That is an argument for versioning the proposal and revalidating it at execution — not for a longer summary.

Which is also why removing prompts is not automatically the wrong move. Approval fatigue is real: a reviewer who clicks through forty dialogs a day is not providing oversight either. Fewer, better-instrumented gates on genuinely consequential actions beat a wall of prompts nobody reads.

The design question is not how many approvals there are. It is whether the person at each one has enough to say no.

An approval you could not have refused was never a control. It was a receipt.

Теги: ai-governance · product-design · systems-thinking · human-oversight