Arrow Trade

Control and governance

What the system is allowed to do — and what it is not

A reliable system is not born from what it is allowed to do, but from what it is forbidden to do.

Types of activity and level of automation

Type of activityWhat the system doesHuman control
Low riskclassifying an incoming request, looking up information, standard replies Acts on its ownSpot checks
Medium riskpreparing a quote, handling a complex request Prepares and proposesApproval required
High riskcontracts, significant payments, legal or people decisions Analyses and assistsA person decides, always

Never automatic, for any client, in any configuration: signing contracts, significant payments, legal decisions, decisions about people — hiring, dismissal, evaluation.

The same table, as it appears in a conversation with a client.
The same table, as it appears in a conversation with a client.

Casual use against professional work

Casual use of AIHow we work
ScopeA general-purpose assistant, the same for everyoneAgents aimed at one service and one specific process
ContextDoes not know the businessWorks on the company’s documents, method and language
Result“Seems useful”, nothing measuredA process that used to cost hours closes in minutes — and the system measures what it does
MethodChanges on its own; invents when data is missingTells what the method provides from what is elaboration, cites sources, states the gap — and never changes the method by itself
ValidationNo gate: the output goes outBlocking human validation on anything that leaves
ControlNobody knows what the agent does, who authorised it, what it can reachInventory of agents and their permissions, role-based permissions, traces out of the agent’s reach
RobustnessThe control breaks at the second attemptControls hold against repeated attempts
SecretsKeys end up in the agent’s contextThe agent sees a reference, not the secret
DataLeaves, and nobody knows whereWhere the material lives is decided with the client
IncidentDiscovered after it has happenedWho detects, who decides, who notifies and in how long — written in advance
The difference is not the quality of the output. It is governability.

Security and control

No privileges by default, minimum access, full traceability.

Permissions of a role

Example: customer support

May

  • read requests
  • look up orders
  • look up products
  • prepare replies
  • send standard replies

May not

  • change prices
  • delete customers
  • make payments
  • see salaries
  • export the archive

Operating limits

Refund under € 50the system may act on its own
€ 50 – 500the system proposes, a manager approves
Over € 500the system may not act — escalated to a person
Permissions, operating limits, and the trace of every step.
Permissions, operating limits, and the trace of every step.

Full trace

Every step is recorded: when the request arrived, how it was classified, which data was read, what was proposed, who approved, when the reply went out.

14:32:11 request received 14:32:12 classified as “support” 14:32:13 records consulted 14:32:14 order 8742 consulted 14:32:16 reply prepared 14:32:18 approved by the manager 14:32:22 reply sent

And not only what the system did, but why, with which data and under which authorisation. That is the difference between a system you can govern and one you have to trust.

Four questions we ask before we touch anything

  1. Where do the traces live — out of the agent’s reach, or inside the same system that can rewrite them?
  2. Do the controls hold against repeated attempts, or does a second try get through?
  3. Who holds the stop, and how long did it actually take the last time it was used?
  4. Does the agent see the secret, or only a reference to it? And who granted that permission?