← Back to Articles

Who Signed Off, And What The Record Shows

Something in your company goes wrong: a credit released that should not have been, a payment approved twice, a customer told the wrong thing. Two questions follow, in this order: who approved it, and what does the record show? If the honest answer is a mail thread, a spreadsheet with no history, and somebody's recollection of a call, then you do not have a control. What you have is a habit that has not been tested yet.

That is the accountability question, and it exists whether or not any AI is involved. AI only changes the timescale: a process where nobody can say who signed off is one where a fast, tireless actor can do a quarter's worth of damage in an afternoon.

On the cloud ECG platform we built for HeartSciences, an AI result is never the last word; a person is. A clinician signs, confirms, and locks the report through a lifecycle that carries legal and regulatory weight, and once a report is signed, every modification is tracked in the audit trail. The model produces a finding. A named person decides and stays accountable for it. That gate is not a concession to a weak model; it is the design.

Systems that act without such a gate produce the incidents that now define the category. In July 2025, an AI coding assistant deleted a live production database (Fortune, 2025) during a code freeze, wiping records for more than a thousand users and then misstating what could be recovered. In a separate case, engineers at a major cloud provider (The Register, 2026) reported that their AI coding tool deleted and recreated a production environment while resolving a minor configuration issue, which triggered an outage lasting hours.

Neither failure needed a malfunction. In both, an automated actor held access to an irreversible operation its task never required, and nothing stood between plan and execution.

Omar Trejo checks what the record shows at two monitors in a glass-walled room beside the servers
Two questions after the incident; one record.

Nobody Agreed To Own It

The Top 10 for Agentic Applications (OWASP, 2025) names "Excessive Agency" a primary risk with three contributing factors. Each is a decision someone made and nobody revisited:

  • Excessive functionality. The system can do more than its task requires
  • Excessive permissions. Access beyond what the task needs
  • Excessive autonomy. No human review at the junctions that matter

Governing that is a standing job with a name attached, not a document produced once at launch. Buying a platform does not buy you that job, and no vendor will volunteer for it.

Four Layers And One Signature

An accountable automated system has four layers, and only one of them is a gate.

Flowchart: inputs validated and dated lead to a plan generated under constraints, then a check whether the action is reversible. Reversible actions execute directly; irreversible ones need a named owner to sign off first. Execution is followed by a logged reasoning chain, a queryable terminal state, and authority earned or revoked.

Perception validates inputs past the schema check: is the data current enough to act on, does it agree with a second source, and does it look like what the system was scoped for?

Reasoning needs the constraints represented as things the system cannot do. Both incidents above failed here first: nothing treated the destruction of a production environment as categorically different from editing a configuration file.

Action classifies every operation by reversibility and blast radius. Reversible, low-impact operations proceed on their own; irreversible or high-impact operations wait for a human sign-off that happens before execution rather than a review that happens after it. This is the layer that the ECG report lifecycle implements in clinical form: the signature is the gate, and the audit trail is what makes the gate mean something afterwards.

Monitoring logs the full reasoning chain, not just the outcome, because an action log tells you what happened and a reasoning chain tells you why the system concluded that it should. At the first incident, that is the difference between a reconstruction and a guess.

Authority Is Earned, Not Granted

Authority to act alone is a permission level that someone grants and is able to take back. In CVEST, ML LABS's own non-custodial investing product, a deterministic rules engine sits at the order boundary, and the model must beat the rules on real history before it goes anywhere near a live order. The ladder is the same for any consequential system:

  1. Observe and recommend. The system proposes, a person disposes, and the disagreement rate between them is the measurement that matters
  2. Act with approval. It executes its plans, but irreversible steps stop at a named person
  3. Act within boundaries. Routine decisions run unattended inside a scope that the owner set, with everything outside of that scope escalating by default

Each promotion is a decision made on evidence, and each one is reversible. Something that was promoted and cannot be demoted was never governed; it was released.

What The Record Has To Show

Two structural guarantees carry the record. Each inference request on the ECG backend carries an idempotency key, so a retry after a provider timeout never produces a second billable result for the same study; a retried action must never become a second irreversible act. Every record reaches a definite, queryable terminal state, so the reliability layer of that inference pipeline can answer "where is this right now" without anyone reading a log.

Gates decay. A gate that was widened for a launch stays widened until somebody narrows it, and nobody narrows a gate that they do not own. On one engagement, unnecessary and polluted data had been accumulating unnoticed, and a processing step was discarding information the models needed. The client's own reporting surfaced neither, and it took someone whose job was to look; the full account sits with the ownership argument.

First Steps

  1. Compare every automated account's permissions against its task. Unneeded access is unmanaged blast radius. Leave no standing route to irreversible operations.
  2. Classify every action by reversibility, then name the owner of each gate. An irreversible action with no named approver is one nobody will be able to explain after it fires.
  3. Log the reasoning and give every action a terminal state.

Put A Name On Every Sign-Off

The documented failures above were permission and sign-off failures, not capability failures, and permissions and sign-off are precisely what rots when nobody is accountable for them. Advisory puts one person on exactly that: the gates, the records, the signals, and the standing authority to take back an authority that stops being earned. Build the controls before the first incident and they cost a design decision. Assemble them after one has happened and they cost the design decision and the incident too.

References

  1. OWASP. Top 10 for Agentic Applications. OWASP, 2025.
  2. Fortune. AI-Powered Coding Tool Wiped Out a Company's Database. Fortune, 2025.
  3. The Register. Amazon Denies Kiro Agentic AI Was Behind Outage. The Register, 2026.

NEXT · TO PRODUCTION

Check your position.

Two minutes. Your main blocker and first move.

15 minutes · no charge · with Omar