← All features
AI Controls & Guardrails

Human review of AI output

Live

Hold AI work product above a risk threshold until a named person approves it — a gate at the point it leaves, not at the point it is generated.

What you get
  • Per-artefact-kind review policy with a risk floor
  • Approval queue with approve and reject decisions
  • Deciding bound to delete on the role matrix — owners and company admins only
  • Off by default, so it is a control you turn on rather than a workflow you inherit
+1 more capabilities below
Overview

What it is.

Set a policy per kind of AI output: whether it needs review at all, and above what risk level. Anything crossing that line enters an approval queue and waits for a person to approve or reject it. The gate sits at egress — where the work product would go to a counterparty — rather than at generation, so ordinary internal use is not slowed down by it.

Deciding is deliberately a high permission: approval requires delete on the role matrix, which the seeded roles give to owners and company admins only. Signing off AI work product that is about to leave the building is the most consequential action in the flow, and it is bound to the strongest permission rather than to a new vocabulary invented for the purpose. The whole thing is off by default.

How it works

Three steps.
End to end.

01
1. Set the policy

Per artefact kind: on or off, and the risk floor above which review is required. Default is off.

02
2. Work queues up

Output crossing the threshold opens a review request and waits.

03
3. Approve or reject

Owners and company admins decide. Managers and members cannot — that is the permission boundary doing its job.

Capabilities

What you get.

  • Per-artefact-kind review policy with a risk floor
  • Approval queue with approve and reject decisions
  • Deciding bound to delete on the role matrix — owners and company admins only
  • Off by default, so it is a control you turn on rather than a workflow you inherit
  • The gate is at egress, not at generation
FAQ

Quick answers.

Does it stop the AI from running?

No. It stops the output from going out unreviewed. Generation is unaffected, which is why turning it on does not slow ordinary internal work.

Can a manager approve?

No, unless you give a custom role delete on the relevant capability. The seeded Manager and Member roles cannot approve AI output.

Related

More in AI Controls & Guardrails.

No model training on your data
Live

We do not train models on customer content. There is no opt-in, because there is no training programme.

Prompt injection defence
Live

User-pasted text is sanitised before reaching the LLM.

Per-org cost guardrails
Live

A monthly AI token quota per plan, an 80% warning by email and in-app, and a hard stop at 100%.

Prompt caching
Live

Stable prompt prefixes are cached. Faster responses, lower bill, passed to you.

Want to try Human review of AI output?
Get started in 60 seconds.

Sign up →All features
I’m Vio. Drop a clause on me.