Human review of AI output
LiveHold AI work product above a risk threshold until a named person approves it — a gate at the point it leaves, not at the point it is generated.
- ✓Per-artefact-kind review policy with a risk floor
- ✓Approval queue with approve and reject decisions
- ✓Deciding bound to delete on the role matrix — owners and company admins only
- ✓Off by default, so it is a control you turn on rather than a workflow you inherit
What it is.
Set a policy per kind of AI output: whether it needs review at all, and above what risk level. Anything crossing that line enters an approval queue and waits for a person to approve or reject it. The gate sits at egress — where the work product would go to a counterparty — rather than at generation, so ordinary internal use is not slowed down by it.
Deciding is deliberately a high permission: approval requires delete on the role matrix, which the seeded roles give to owners and company admins only. Signing off AI work product that is about to leave the building is the most consequential action in the flow, and it is bound to the strongest permission rather than to a new vocabulary invented for the purpose. The whole thing is off by default.
Three steps.
End to end.
Per artefact kind: on or off, and the risk floor above which review is required. Default is off.
Output crossing the threshold opens a review request and waits.
Owners and company admins decide. Managers and members cannot — that is the permission boundary doing its job.
What you get.
- ✓Per-artefact-kind review policy with a risk floor
- ✓Approval queue with approve and reject decisions
- ✓Deciding bound to delete on the role matrix — owners and company admins only
- ✓Off by default, so it is a control you turn on rather than a workflow you inherit
- ✓The gate is at egress, not at generation
Quick answers.
No. It stops the output from going out unreviewed. Generation is unaffected, which is why turning it on does not slow ordinary internal work.
No, unless you give a custom role delete on the relevant capability. The seeded Manager and Member roles cannot approve AI output.
More in AI Controls & Guardrails.
We do not train models on customer content. There is no opt-in, because there is no training programme.
User-pasted text is sanitised before reaching the LLM.
A monthly AI token quota per plan, an 80% warning by email and in-app, and a hard stop at 100%.
Stable prompt prefixes are cached. Faster responses, lower bill, passed to you.