Human in Command

A person approves delegated work before it starts and accepts it after.

AI Investigation and ARRTECH SOAR · Updated Sep 23, 2026

Who approves what the AI does?

For delegated work, a person does, twice: an administrator approves each task before any agent sees it, and a person accepts the finished work. In ARRTECH SOAR, a playbook waits at each Operator node for a person's choice.

Diagram: the approval lane runs Request by email, Approve by an administrator, Work by an agent read-only, then Accept by a person. Below, a playbook reaches an Operator node where a person chooses, then continues. Approve, Accept and Operator node are highlighted as the points where a person decides.

Controls

  1. A request arrives.

    A person asks by email. Your policy checks the request, without a model call.

  2. An administrator approves.

    No agent sees a task until an administrator approves it.

  3. The agent asks.

    When an agent needs a decision, the task waits for the right person.

  4. A person accepts.

    Work returns in review, never resolved, until a person accepts it.

  5. The suite waits.

    ARRTECH SOAR waits at each Operator node. ARRTECH DLP can hold a file or message until a manager releases it.

Limits

Judgment

The lane decides who approves, not whether an approval is right. Accountability stays with your people.

Status

The delegated-work module is in early access.

Verify

Each step leaves a record.

Tasks

Every approval, question, acceptance and reopening on a task is recorded, so you can see who decided at each step.

Playbooks

ARRTECH SOAR's history shows who chose which Operator option and when. The Operator Requests page lists decisions still waiting.

Request outcomes are covered on Agent Permissions.

Standards

Naming a clause is not a claim of certification.

EU

Article 14 of the EU AI Act asks that people can monitor, interpret, override and stop a high-risk system. Approval before and acceptance after are where a person holds those decisions.

NIST

AI RMF MAP 3.5 asks for documented human oversight, and MANAGE 2.4 for a way to disengage a system. This page documents both.

Related

Autonomy Levels

Agent Permissions

Usage Policy

Cyberdroid AI Investigation

Contact
ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.