CHECK THE COMBINATION

One agent should not quietly become both sides of a check.

Understand separation of duties for AI agents with a supplier-record example, combined-scope review, and evidence for human checkpoints.

DutyGraph editorial · September 6, 2026

Why the combination matters

A process can separate preparing a change from approving it. When an agent receives permissions across several systems, that separation may disappear. Reviewing one permission at a time can miss the combined capability. The relevant rules depend on the company and process.

An illustrative supplier example

One person prepares a supplier record. Another verifies bank details. A separate authorized person approves activation. An agent that can create the record, edit the bank details, and approve activation could bypass the intended checks even if each permission has a familiar name.

Map actions to the control

Write the sensitive action, its resource, the rule requiring separation, and the independent reviewer. Link each proposed agent scope to those items. Inspect the human owner’s other roles and any shared credentials or related agents that could complete the other side.

A human checkpoint must be real

A label reading “human review” is not enough. Identify who can approve, the exact information they see, the version they approve, and what prevents execution before their decision. Test that the requester cannot approve their own action when policy requires independence.

Keep exceptions visible

If policy allows an exception, record its approver, reason, duration, compensating checks, and review date. Do not silently widen an agent’s scope because a task is inconvenient. Unknown or conflicting authority should remain unresolved until the appropriate owner decides.

What DutyGraph contributes

A reviewed work map can show which people prepare, check, approve, and hand off a task. That context can inform an access-policy review. The current governance sample uses fictional records; it does not establish compliance or replace a live IGA policy engine.

Sources

Primary references used in this guide.

Keep exploring