SigmaTrust Docs · AI Agents & Approval Gates
AI Agents & Approval Gates
What the AI workforce does — and the human controls it operates under.
AI compliance agents
Agent roles handle defined workstreams — drafting, enrichment, monitoring, summarisation — and report their work in a daily standup visible to administrators.
Approval gates before outbound action
Agent-prepared outbound work queues for explicit human approval before anything leaves the platform. The gate is a structural control, not a setting — unreviewed output does not send.
Collector agents
Scheduled collectors gather evidence and operational signals (site health, rankings, campaign data, mailbox events) so reviews start from current data rather than requests for screenshots.
Boundaries by design
Agents operate inside tenant scope with the same data-access enforcement as human users, and their actions land in the same audit trail.
FAQ
Can the AI act without human approval?
Outbound actions (email, external submissions) require human approval at a gate; internal drafting and analysis run autonomously but visibly, with output attributed and logged.
What model of oversight do auditors get?
Agent actions are attributable in the audit trail like any user, and the daily standup summarises what ran — the oversight evidence AI-governance frameworks (ISO 42001, EU AI Act organisational duties) ask about.
