AI and Agent Controls

Human Approval on Sensitive Actions

Actions that change state in a connected system can require an approver before they run. Sensitive actions are gated by default and the gate is configurable per workspace, so an administrator decides where the agent acts on its own and where a person signs off first.

Framework requirements this speaks to

  • ISO 27001 A.5.15 (access control)
  • NIST AI RMF MANAGE 4.1
  • EU AI Act Art. 14 (human oversight)

Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.

Need the evidence behind this?

Our SOC 2 report and ISO 27001 Statement of Applicability are the authoritative record. Both are available under NDA, by email - we do not host them as downloads.