Governance
Autonomous where it makes sense. Human where it matters.
AI does the work. Humans approve the consequences.
Human oversight
Every agent operates within defined boundaries. Consequential actions are routed to the appropriate person for review and approval before they execute.
Least-necessary access
Agents are configured with the minimum permissions required to perform their work. Access is scoped to specific systems, data sets and action types.
Approval points
The design phase defines where human approval is required based on the action type, risk level and your business rules. These controls are configured before the agent goes live.
Auditability
Agent actions can be reviewed and traced where supported by the underlying platform. Governance reviews are part of ongoing AgentOps.
Operating boundaries
Each agent has clear instructions defining what it can and cannot do. These boundaries are refined over time as you build confidence in the agent.
Testing protocols
Agents are tested against real scenarios before going live. Governance controls are validated as part of the deployment process.
Progressive governance
Routine actions
Read, search, classify, summarise, compare, prepare, reconcile, flag
These can often happen automatically.
Controlled actions
Create internal tasks, update certain records, request missing information, prepare documents, route work
Controls depend on your business policy.
Consequential actions
Important external communications, financial approvals, payments, contractual actions, sensitive record changes, regulatory submissions
Routed to the appropriate person for approval.
This is Ditto's design philosophy, not legal advice or a universal compliance requirement.