Get access
← All articles

Who approved the automated action?

Most teams talk about AI governance at the policy level. The operational risk is simpler: money or sensitive data moves through automation, and nobody can answer who allowed it.

Listen
0:00 / 1:10

Most teams talk about AI governance at the policy level.

The risk I keep seeing is simpler: money or sensitive data moves through an automated step, and nobody can answer who allowed this on a normal Tuesday.

Not model safety. Not a chatbot on the website. The gap is proof when an action actually runs.

What audit actually asks

When something goes wrong six months later, internal audit does not ask for your AI principles deck. They ask:

  • Who approved this payout?
  • What rule was in effect?
  • Can you reconstruct the chain without searching email?

If the answer is "we think someone in ops signed off in Slack," the governance program did not help.

Routine should pass. Exceptions should be recorded.

Good control does not mean blocking every transaction. It means the normal path stays fast, and only anomalies get a named approver plus a record you can export.

That is the layer we build at Salanor: automate the workflow, keep the proof.