Implementing Agentic AI Ep 4: Guardrails and Review
Part 4 of 5. Propose, approve, execute, review - the four-beat ritual that makes agent work reviewable, and the four properties auditors ask about: owner, intent, scope, lifecycle. On the procurement floor, where a gate rejects the renewal nobody wanted.
Course materials
The Working Playbook — template
The five-row playbook template from the course, with the five pocket rules on the last page. Print it, fill in one row for one boring, busy, reversible process this month.
Sign in free to downloadTranscript
Procurement's renewal agent had one job: track contract end-dates and
prepare renewals before they lapse. Thorough little thing.
Which is why, in week three, it dutifully prepared the renewal for the
warehouse-cleaning contract — Cleanco, to its few friends — the one the
whole company had spent six months trying to exit.
Here's the difference between this episode and every cautionary tale
you've heard: the renewal didn't go out. It arrived as a proposal, at a
gate, where a human read it and laughed, and clicked reject.
The agent wasn't wrong. The system was right. That's what today builds.
Guardrails and the review ritual. Part four of five.
For everyone who'll be accountable when an agent acts — and for the
auditors and boards about to start asking questions with framework
names in them.
In five minutes: the four-beat ritual that makes agent work reviewable —
propose, approve, execute, review — the four properties every agent must
have before it ships, and how one page of your playbook answers an ISO
audit. We're in procurement, where the gates were already a way of life
before agents arrived.
The ritual has four beats, and it never varies.
Propose: the agent prepares the action — the renewal, the refund, the
letter — and stops.
Approve: a named human reads the proposal and lets it through, or not.
Execute: only now does anything touch the real world.
Review: everything lands in a ledger — what was proposed, who approved,
what changed — sampled and read by a person, weekly.
Run the first weeks propose-only — nothing executes at all — and let
the approval rate be your graduation metric: when nine proposals in ten
sail through unchanged, the execute beat is earned, not assumed.
The gates carry one more quiet job. Episode three's planted
instructions — the ones that hide in what an agent reads — can propose
whatever they like here. They just can't execute.
The rhythm matters more than the tooling. Teams that keep the four beats
survive their agents' mistakes. Teams that skip a beat meet the runaway
intern: without that first gate, our cleaning-contract renewal goes out
on a Tuesday, surfaces at invoice time months later, and is unwound at
legal's hourly rate.
The same colonnade runs the whole building.
HR, last episode: the offer letter waits at the gate — that outbox catch,
made systematic instead of lucky.
Support: refunds above the threshold queue for approval; below it, they
flow — the gate placed exactly where the boundary line was drawn.
Finance: payment proposals stack neatly at accounts payable's gate every
morning; ten minutes of human review, nine thousand invoices of
throughput.
Gates aren't friction. Placed well, they're the reason everything else is
allowed to move fast.
Now the part your auditors will ask about, sooner than you think.
The governance frameworks converging on AI — the NIST risk framework,
the ISO forty-two-thousand-one standard, the European Union's AI Act, its
obligations already phasing in — none were written for agents. Applied to agents,
they distil, in our reading, to four properties, per agent, no
exceptions:
A named owner — a person, not a team inbox.
A clear intent — what it's for, written down.
A bounded scope — what it can touch, and nothing else.
An explicit lifecycle — reviewed on a date, retired on purpose, never
abandoned running.
Owner. Intent. Scope. Lifecycle. Notice: your mission brief from episode
three already wrote the middle two.
Why insist? Because of where the industry actually is.
Most organisations surveyed this year now run agentic AI somewhere in
production — while roughly six in ten still have no formal governance
around it. Production without governance isn't
boldness; it's a ledger nobody's reading.
And when something goes wrong in that gap, the question won't be "was the
model good" — it'll be "who owned this, what was it allowed to touch, and
who approved that?" Four properties. You want the answers written before
the question arrives.
Beat four deserves its own minute, because it's the one that decays.
Decay looks like this: skipped once in a busy week, twice in a busy
month — by spring the ledger is a diary nobody reads.
The other decay is quieter: the approve click that stops being a read.
If your approval rate sits at one hundred percent and never moves,
nobody's reviewing — they're waving.
Review means: a ledger every agent writes to automatically, and a
standing appointment where a human reads a sample. Twenty minutes, weekly.
What was proposed and rejected — that's your boundary quality. What was
approved — that's your trust curve. What changed after execution — that's
your audit trail, already written, the day anyone asks.
The procurement reviewer who laughed at the cleaning contract? That laugh
was the system's immune response, on schedule.
Pocket rule number four — the shortest and the sternest:
Owner, intent, scope, lifecycle — or it doesn't ship.
Four blanks on a form. If any one of them is empty, the agent isn't
unfinished paperwork — it's an unowned actor with undefined reach and no
retirement plan, which is the polite description of every AI incident
you've read about.
Fill the blanks. Then ship with confidence.
Row four goes into the playbook.
Process: contract renewals. The ritual: four beats, drawn as gates.
Owner: the procurement lead, by name. Intent and scope: lifted from the
brief. Lifecycle: reviewed quarterly, retired on contract-system
migration. Ledger: live, sampled Fridays.
One row — and read it again slowly, because that row is a completed audit
answer. When the assessor asks about your AI controls, this page is the
exhibit.
Four beats, four lines.
The ritual: propose, approve, execute, review — and it never varies.
Gates placed at the boundaries are why everything downstream moves fast.
Four properties, per agent, no exceptions: owner, intent, scope,
lifecycle.
And the industry gap — production without governance — is exactly the
space your playbook page closes.
Next time: the finale — prove it, then scale it.
Up to the top floor, sales operations, and then into the boardroom — where
someone is going to ask the only question that funds year two: "what did
the agents actually earn us?"
You'll learn the baseline habit that makes that question easy, the four
numbers boards accept, and the flywheel that turns one boring win into a
programme. And the playbook — five rows full — becomes yours to download.
Five minutes. Bring your numbers.