Decision workshops

Design the Human-AI Operating Model

A workshop to decide which decisions AI may assist or automate, who approves exceptions, and who can stop a workflow, recorded as a decision-rights matrix.

Direct answer

Direct answer: Human–AI operating model

An organisation using AI across several functions needs one answer to three questions. Which decisions may be assisted or automated? Who approves the exceptions? Who can stop a workflow? Without that answer, each team invents its own rules and accountability blurs. This workshop produces a decision-rights matrix, escalation paths and a register of the policy questions the organisation has not yet resolved.

The question

“Which decisions can be assisted or automated, who approves exceptions, and who can stop a workflow?”

Who it is for

Leadership teams, risk and operations leads, and AI programme owners coordinating AI use across functions.

Decision rights in a human–AI workflow

Decision rights in a human–AI workflow Routine step: Reversible, observed; Judgement step: Context-dependent; High-impact step: Money, customers, safety; Decision-rights matrix: Who acts, approves, stops; Automate: With logging and limits; Assist: AI drafts, person decides; Approve: Named approver required Routine step Reversible, observed Judgement step Context-dependent High-impact step Money, customers, safety Decision-rights matrix Who acts, approves, stops Automate With logging and limits Assist AI drafts, person decides Approve Named approver required

What you leave with

A decision-rights matrix, escalation paths, and an unresolved-policy register.

  • 01 A decision-rights matrix: for each decision class, whether AI informs, recommends, acts with approval, or acts and reports
  • 02 Escalation paths naming who approves exceptions and who can pause or stop each workflow
  • 03 An unresolved-policy register of questions the organisation must still decide, with owners
  • 04 A short set of principles teams can apply to new AI use without returning to leadership each time

How it runs

Format, method, and preparation

Duration
A preparation call and a half-day or full-day workshop, followed by the written matrix and register
Delivery
In person in the UK or remote
Participants
Leaders from the functions using AI, with risk, legal, and operations representation
01

Classify the decisions

Group decisions by consequence, reversibility, customer or employee impact, and regulatory exposure rather than by tool.

02

Set decision rights

For each class, agree how far AI may go, who approves, and what evidence must be kept.

03

Design escalation and stopping

Name who handles exceptions, who can stop a workflow, and how a stop is triggered and recorded independently of the model.

04

Register what is unresolved

Record the policy questions the session could not settle, assign owners, and set dates for decisions.

Useful to have ready

  • →A list of current and proposed AI uses across functions
  • →Existing delegation of authority, risk, and incident-management policies
  • →Participation from each function whose decisions are in scope

Evidence

What this draws on

Public reference system

CloseGate

A Python and MCP policy layer with action tiers, segregation of duties, materiality routing, mandatory approval for irreversible actions, and hash-chained replayable audit. No published independent certification or customer deployment.

Inspect the source ↗
Public reference system

Regulus

A runtime-governance architecture covering agent identity and purpose, policy, PII, residency, model-risk tiers, kill switches, human oversight, and evidence export. Controls are mapped to NIST AI RMF and ISO/IEC 42001; mapping is not certification.

Inspect the source ↗
Delivery experience

Regulated banking AI at Aveni

Architected enterprise banking AI with conduct-risk workflows, evidence generation, human review, escalation, evaluation, versioning, and release controls. Part of the Aveni team in the first FCA Supercharged Sandbox cohort; the FCA lists Aveni as an accepted firm, which is not an FCA endorsement or certification.

Inspect the source ↗

Scope and limits

What this is not

  • —The matrix is the organisation’s own design. It is not a legal or regulatory compliance opinion and does not certify any workflow.
  • —Engineering the approvals, logs, and stop controls into systems is separate delivery work, available through dipankar.co.
  • —Items in the unresolved-policy register remain open until the named owners decide them.

If the need is different

Common questions

Answers before you commission

What is a human–AI operating model?+

An agreed description of which decisions AI may inform, recommend, or take, who approves exceptions, who can stop a workflow, and what evidence is kept. It turns principles about human oversight into named responsibilities.

How do you decide which decisions AI may automate?+

By consequence and reversibility. Low-impact, reversible, well-observed decisions can be automated with reporting; material, sensitive, ambiguous, or irreversible decisions need human approval or remain human.

Who should be able to stop an AI workflow?+

Named people with operational responsibility, through a mechanism that works independently of the model. The matrix records who they are and how a stop is recorded and reviewed.

What happens to questions the workshop cannot settle?+

They go into an unresolved-policy register with an owner and a decision date, so gaps in policy are visible rather than left to individual teams.

Related

Next step

Describe your audience and decision

A short written brief is enough to establish fit. I reply personally, and say plainly when the work belongs elsewhere or is not worth commissioning.

Executive or decision workshop: what to include

  • →Sponsor and role
  • →Audience: roles, number of people, and familiarity with AI
  • →Decisions the session must support
  • →Current AI activity, tools, or disagreements
  • →Preferred format, length, date, and location or remote
  • →Pre-read or preparation time available
  • →Budget range
  • →Recording or reuse requirements