AI Approval Gate Matrix
A matrix that maps AI actions to the level of human review they need, so the routine flows freely and the consequential calls get a person.
Not every AI action needs the same level of oversight, and treating them as if they do either slows everyone down or lets risky actions through. An approval gate matrix sorts actions by how much they could affect someone, then assigns each tier the review it deserves. This template gives you four tiers you can rename, the questions that place an action in a tier, and examples for each. Adapt the tiers to how your business actually works.
Inside the editable version
- An editable four-tier matrix with the review level for each
- A set of placement questions to sort any action into a tier
- Examples for each tier you can swap for your own
- A note on logging and exceptions you can adapt
The template
Why gate by tier
An approval gate is a checkpoint where a person reviews what an AI tool is about to do before it happens. Putting a gate on every action would slow work to a crawl, and putting one on none would let consequential actions through unchecked. The fix is to sort actions into tiers by how much they could affect a person, a client, or the business, and to match the level of review to the tier. Routine, low-impact actions flow with little or no review. Actions that change records, touch regulated data, or act on behalf of someone get a human in the loop.
Questions that place an action in a tier
To decide which tier an action belongs in, ask: Does it only read or draft, or does it change something? Does it touch regulated or personal data? Does it make or recommend a decision that affects a person? Can it act on its own, or does it always stop for a person? The more yes answers, and the more serious the yes, the higher the tier. When an action sits between two tiers, place it in the higher one until you have evidence it is safe to move down.
Tier 1: no gate (read and draft only)
Actions that only read public or internal non-regulated information and produce a draft for a person to use. Review level: none required, because a person always decides what to do with the output. Examples: summarizing a public article, drafting an internal note, suggesting code for a developer to review. The control here is simply that nothing the tool produces reaches a client or a live system without a person choosing to send it.
Tier 2: light review (output leaves the building)
Actions whose output goes to a client, a regulator, or the public, but which do not change any system or touch regulated data. Review level: a named person reads and approves the output before it goes out. Examples: an AI-drafted client email, a public-facing summary, a proposal section. The reviewer checks facts, tone, and any commitments, and is accountable for what is sent.
Tier 3: approval gate (changes data or touches regulated data)
Actions that write to a system, change a record, or involve personal or regulated data. Review level: a person must approve the specific action before it executes, and the action is logged. Examples: updating a customer record, sending a message to a list on behalf of the company, or processing a file that contains personal data. Access for these actions is scoped to the minimum the task needs, and the approver is someone who understands the consequence of the change.
Tier 4: senior sign-off (decisions about people or autonomous action)
Actions that make or recommend a decision affecting a person, or that let a tool take a series of actions on its own. Review level: sign-off from [senior owner] before the use case goes live, plus a human check on individual high-stakes outcomes. Examples: screening applicants, deciding eligibility or pricing for a person, or an agent that completes a multi-step task without stopping. These get the most scrutiny because the cost of a wrong or unfair outcome is highest and hardest to undo.
Logging, exceptions, and review
Log Tier 3 and Tier 4 actions so you can answer later who approved what and when. Allow an exception path for urgent cases, but require that the exception is recorded and reviewed afterward, so a shortcut taken under pressure does not quietly become the norm. Review the matrix when you adopt a tool that does something new, and at least once a year. The tiers are a starting point. Rename them, merge them, or split them to match how decisions actually get made in your business.
This is a starting template, not a finished policy. Adapt it to how your business actually works, and have it reviewed by the right people before you rely on it.
Want this built into how your AI actually runs?
A template is a starting point. A short working session turns it into a plan: where AI creates leverage for you, and what guardrails to put in place first.