Lesson 16 / 25

Risk Tiers and Approvals

Classify tools as read, write or destructive and require approval accordingly.

Match friction to risk

Not every tool deserves the same care. Read tools can run freely. Write tools change state and often need logging or a confirmation. Destructive or irreversible tools (deleting data, sending money, emailing customers) should need explicit human approval. Unknown tools default to the strictest tier.

Layers of defence

Assume mistakes and manipulation will happen, and limit what any single failure can do.

Four layers: permissions, approvals, sandbox, monitoring.
Figure 5.1 — Permissions, approvals, sandbox and monitoring.

An approval gate

This ran as shown. Reads pass; send_payment and the unknown tool both need approval, because unknown names fall to the strictest tier.

RISK = {"get_balance": "read", "convert": "read",
        "send_payment": "write", "delete_account": "destructive"}

def needs_approval(name):
    return RISK.get(name, "destructive") != "read"

print([needs_approval(n) for n in ("get_balance", "send_payment", "unknown_tool")])

Output:

[False, True, True]

Show the exact action

An approval prompt should show the tool and its real arguments ("send 5,000 INR to account 8841"), not a vague summary. People approve what they can see.

Quick check: How should an unknown tool be treated by default?

  • As read-only
  • As free to run
  • As the strictest tier needing approval
  • Ignore the safety rules
Answer

As the strictest tier needing approval — Failing closed means a forgotten classification cannot silently allow a risky action.