Approval gates people don’t route around
Governance fails socially before it fails technically. Notes on designing thresholds that survive contact with a busy quarter.
The graveyard of corporate controls is full of well-intentioned gates: the PO approval everyone batches on Friday, the security review that teams start after the launch date is fixed, the legal checkbox with a keyboard shortcut. Controls decay when their cost lands on the wrong people at the wrong moment.
We think about gate design as much as gate enforcement. A few principles have survived our design partners’ real quarters.
Every gate people route around was priced, placed, or timed wrong.
Principles that held
Gate the commitment, not the conversation. Agents negotiate freely below thresholds; the gate fires once, at the moment of binding, not on every message.
Make the reviewer named, not a queue. "Pending with R. Osei, closes Thursday 09:01" behaves differently from "pending with legal".
Put the window in the protocol. Approvals expire and escalate to a deputy on a recorded schedule — so the gate cannot become the place deals silently die.
Never charge per gate. A control with a per-use fee invites routing around it; flat pricing keeps the incentive aligned with governing everything.
What we refuse to build
Auto-approval "for low-risk items the model deems routine". The runtime enforces limits; it does not interpret them. The day the gate starts deciding, it stops being a gate.
More field notes
“Who approved this?” — the question that ends agent pilots
Agent pilots rarely die from bad output. They die the first time finance or legal asks a question nobody can answer.
The Subchain team
5 min read