Four-Gate Approval Model
Each write-back action is assigned to one of four approval gates based on risk level:Gate assignments are configured per action type by administrators. The platform enforces the assigned gate, and it cannot be bypassed at runtime.
Approval Workflow
1
User initiates action
A user requests a write-back operation through the platform (e.g., “Create a purchase order for 500 units of part X”).
2
System classifies the action
The platform identifies the action type and its assigned approval gate.
3
Dry-run simulation (optional)
The user can request a dry-run to see exactly what would change without writing any data.
4
Approval gate enforced
Depending on the gate, the action either auto-executes, requires user confirmation, manager approval, or dual-control sign-off.
5
Execution and audit
Once approved, the Action Agent executes the operation. The full lifecycle is recorded in the audit trail.
Dry-Run Capability
Any action can be simulated before execution. The dry-run:- Shows exactly what data would be created, modified, or deleted
- Executes against the target system in read-only mode where supported
- Produces the same output format as a live execution, clearly labeled as a simulation
- Is logged in the audit trail as a dry-run event
Rollback Declarations
Every action declares its reversibility before the user confirms execution:
The reversibility declaration is displayed to the user and approver before execution. Irreversible actions require explicit acknowledgment.
Separate Credentials
Action Agents use write-capable credentials that are entirely separate from read-only data-source agent credentials:
Credentials are stored within each agent’s isolated container. No credential sharing occurs between read and write agents.
Action Audit Trail
Every action lifecycle event is recorded in the immutable audit trail:Recorded for every action
- Who initiated the action
- What the action would do (parameters, target system)
- Which approval gate was required
- Who approved or rejected (and when)
- Dry-run results (if requested)
Recorded on execution
- Exact operation executed
- Target system response
- Success or failure status
- Rollback eligibility at time of execution
- Timestamp for every step