Suppose a team has finished an AI-assisted planning brief while its regular approver is away. The recommended next step falls outside the usual process. The person preparing it can explain the recommendation. Nobody present knows who can authorise the exception.

There may be a policy covering AI use. There may even be a named owner for the process. The team still has a practical problem to solve before work can continue.

This is a useful place to begin a conversation about governance. What arrangements would allow these people to act within their authority, and what should happen while they wait for a decision?

Useful governance gives people a shared understanding of those arrangements. It also gives leaders a way to find out whether they actually work.

Separate the responsibilities

Several kinds of responsibility can sit behind one AI-assisted task. Being clear about the differences avoids placing every unresolved question with whichever person happens to use the tool.

Someone needs to maintain the source information. That includes identifying the current version, dealing with conflicting material and making changes visible to the people who rely on it. This person needs a practical way to notify the workflow owner when a change could affect the work.

The workflow owner looks after how the task moves from start to finish. They need to ensure the necessary checks can happen, that people have suitable access and that unresolved work reaches someone able to deal with it. If the process repeatedly breaks down between steps, it belongs within their responsibility to improve it.

Approval of the consequences may belong to another person. A checked document could still contain a recommendation that requires a separate decision before anyone acts. Being satisfied with the information does not automatically give the reviewer authority to make that decision.

In a small team, one person may hold more than one role. The distinction still helps. They should know which responsibility they are exercising, what authority comes with it and who can step in when they are unavailable. More consequential work may require independent approval.

Make the boundaries usable

People need to know which tools and information are permitted for the task, who can access them and what the output may be used for. Boundaries should also make clear where AI assistance ends and a human decision is required.

Keep those instructions close to the work. A short note beside the task template or in the usual workspace may be more useful during a busy day than expecting people to search a long policy document. It should point to the authoritative guidance where needed.

Access needs to match those expectations. If a person is responsible for checking the approved source but cannot open it, the control cannot operate as intended. If broad access exposes information the task does not need, the arrangement needs attention too.

Agree on an exception route before it is needed. State what the person should pause, who receives the issue and what to do if that person is unavailable. An exception should reach someone with the authority to decide it. A colleague’s willingness to help is not enough.

The route should leave a useful record of the decision, including any limits attached to it. Permission for one unusual case should not silently become permission for every later case.

Walk through an ordinary case together

Choose one low-risk workflow and bring together the people who supply its information, do the work and receive the result. Include the person who decides whether the next action can proceed.

Use approved demonstration material or a fictional example. Follow a normal case from the point the task begins. Open the source people are meant to use. Check that the relevant person can access it. Show where the output goes and what the recipient needs before accepting it.

At each hand-off, ask the receiving person to demonstrate their next step. This can reveal gaps that an agreed process description leaves hidden. Someone may have been expecting evidence that nobody was asked to retain, or an approval may depend on access the approver does not have.

Keep a simple note of any gap, who will resolve it and how you will check the repair. Naming the responsible person is a beginning. Seeing the repaired step work provides more useful evidence that the arrangement can be relied on.

Then rehearse an exception

Now rehearse an exception using the same example. Make the usual approver unavailable and introduce a recommendation that falls outside the normal process, as in our opening scenario. Follow the actual exception route rather than discussing what people would ideally do.

Can the team find an authorised substitute? Which work must pause while that person considers the exception? Will the recipient know what cannot yet be acted on?

Also consider recovery if a problem is discovered after the output has moved on. Agree how affected work can be identified, who must be told and who decides whether a correction is sufficient. Where appropriate, retain a workable way to complete the task without AI assistance. Practise finding and using it.

Set a clear condition for resuming the normal process, with responsibility for confirming that the problem has been addressed. Otherwise a pause can either last indefinitely or end through assumption.

Keep the effort proportionate

The controls should reflect what could happen if the work is wrong or used beyond its intended purpose. A low-risk preparation task may need a modest set of checks. A consequential decision may need restricted access, stronger evidence and independent authorisation.

Adding approval steps everywhere can make it harder to see where judgement is genuinely needed. Start with the points where an error could travel or an action could exceed someone’s authority, and make those points work reliably.

You do not need to settle every governance question in one meeting. Choose a single workflow and walk it through with the people involved. Repair the first gap you find, then try that part again. The aim is for the next person doing the work to know how to proceed, including when something unexpected happens.