A WORKED EXAMPLE

Follow the request all the way to the limit.

A practical agent approval workflow: request, work context, scope review, approval, issuance, and evidence of downstream enforcement.

DutyGraph editorial · September 6, 2026

A request is not an authorization

A procurement analyst asks for an agent to prepare supplier records. The request describes the problem, desired output, and systems involved. It does not itself permit the agent to change those systems. This example is illustrative.

1. Read the work context

Link the request to the person’s current task: receive a packet, check required information, and prepare a draft for review. Verify the person’s identity and role from the appropriate sources. Preserve the distinction between an interview account and an approved policy.

2. Propose a narrow scope

List each resource and action required. Reading an approved folder and creating a draft are different from updating bank details or activating a supplier. Compare requested access with the person’s permitted delegation and company policy. Stop when a required source is missing or stale.

3. Check combined authority

Review the entire proposed scope. Separate actions can become risky when combined: create a supplier, change its payment details, and approve it. Ask whether the agent or its human owner could control both preparation and approval. Record the policy and any required independent checkpoint.

4. Review the exact manifest

A reviewer with the required authority inspects the task, source evidence, included actions, excluded actions, and lifecycle conditions. They can trim or reject the request. The approval must bind the exact version; changing its scope requires a new review.

5. Verify issuance and operation

A production workflow needs supported integrations to create the identity, issue the permitted access, enforce the boundary, and record outcomes. A saved approval is not proof that provisioning succeeded. A failed or uncertain response should remain visible for reconciliation.

6. Test a change and a stop

Change the owner’s role or expire the approval in a controlled test. Confirm that the relevant access is removed and the action is blocked downstream. DutyGraph’s current governance sample illustrates the request and manifest stages with fictional records and simulated issuance. Live enforcement remains a separate integration requirement.

Sources

Primary references used in this guide.

Keep exploring