6 min readAI Agents · Cybersecurity
AI Agent Approval: Five Questions Replace the Committee
By Michelle Savage, Experience Design Director, PayPal

TL;DR: Security keeps getting named the approver for AI agents without anyone defining what approval means, so requests pile up and teams route around the queue. Replace the committee with five yes-or-no questions in writing: identity, scope, data, failure response, and owner. A requester can answer them in an afternoon.
Last updated October 5, 2026. This piece was rebuilt from the ground up around the five criteria, so you can publish them this week and shrink the queue.
"Everybody says security, you need to approve." A client said that, then said the harder part out loud: when somebody knocks on his door with an agent, he doesn't know what approving it would mean. No test, no list. Just a queue and a lot of goodwill. That's the real state of AI governance in most companies. Not resistance, not recklessness. A bottleneck made out of an undefined word.
Why did security end up as the AI agent approver?
Because AI sounds like a technology problem, so it got handed to technology teams by default. One client kept hearing it as a question: AI sounds like technology, so IT will do all of that, right? But most AI agent decisions are business decisions wearing a technical costume. Which data can this touch? What's the cost of it being wrong?
Security should have a seat. It shouldn't be the only seat, and it shouldn't be the seat that decides whether a marketing team gets an agent. What happens instead is predictable: security becomes the place requests go to wait. Nobody wrote that rule. It formed on its own, because security was the only function willing to say no. One leader put his position plainly: he had no authority to play the bad cop, and he was being asked to gate something he couldn't actually gate.
How long does AI agent approval take today?
Months, in the places that built a committee for it. On a 2026 call, a client walked through his process. Use cases go to a board. The board deliberates, then runs a question-and-answer round. Somebody raises tool overlap, which restarts the discussion. If the tool is external, a separate supplier review stacks on top. Nothing in that chain is unreasonable on its own. Stacked, it produces a timeline the business won't wait for.
So the business doesn't wait. An on-hold posture doesn't stop AI adoption. It relocates adoption somewhere with no logging, which is how you end up with governance that exists on paper and nowhere else. One security leader at a large enterprise summed up his year: the agents are outrunning our ability to govern them. He wasn't describing a crisis. He was describing a Tuesday.
What are the five criteria for approving an AI agent?
Five yes-or-no questions with written answers. If a requester can answer them, the agent is approvable at some level of autonomy. If they can't, you've found the actual problem without spending a committee meeting on it.
Question | What a passing answer looks like | Automatic no |
Who is it? | Its own identity, separate from the person who launched it | A shared human credential touching production |
What is it allowed to do? | Named systems and named actions: "read contacts, no export, no write" | "Access to the CRM" |
What data does it consume and produce? | Sources and outputs listed, memory included | An agent that remembers customer data nobody classified |
What happens if it goes wrong? | Who gets told, how fast, who can stop it, what stopping costs | "We'd notice eventually," at high autonomy |
Who owns it? | A person's name | A team |
Then set autonomy against the answers. Weak answers get a narrow agent with a human approving each action. Strong answers earn more room. Approval stops being yes or no and becomes how much, and the requester can see exactly what would move them up. That's the same evidence-based path as the Autonomy Ladder in how security says yes to AI agents, and the owner question gets its full treatment in who owns your AI agent.
Doesn't writing criteria slow the business down?
It speeds things up, and the argument that wins isn't the safety one. A client opened with the standard objection in 2026: this'll slow me down. What turned him was arithmetic, not a risk lecture. An incident stops everything for weeks. A criteria document stops one request for two days. The first AI incident is a bigger brake than governance ever is.
There's a second effect people don't expect. Published criteria shrink the number of requests that need a human decision at all. Most agent requests are small and obviously fine. When the rules are written, those approve themselves, and the security team spends its attention on the four that scare them.
And the published document changes the developer relationship. Today, developers connect an agent and get it working, security hears about it afterward, and the control arrives as an obstacle to something already delivered. Both sides are right, which is why the argument goes nowhere. If a developer can read one page on Monday and know exactly what their agent needs, security stops being a gate and starts being a spec.
What can you do in the next week?
Write the five questions on one page.
Use the ones above or your own. What counts is that they exist in writing before the next request arrives.
Time your last five approvals.
Days from request to decision. Show the number to whoever owns the committee.
Define a fast lane.
The class of agent that skips the committee: no production data, no write access, no customer contact, no ability to spend money. That's most of your queue.
Publish where developers already look.
The wiki nobody reads doesn't count. Put it in the repo template or the platform onboarding page.
Name what security is deciding.
Security decides whether the controls are met. The business decides whether the risk is worth it. Writing that down ends a lot of arguments.
Frequently asked questions
Who should approve AI agents if not security?
Security approves the controls. The business owner approves the risk. Combining the two is what creates the bottleneck. Security's answer should be "these controls are met" or "here's what's missing," never "you may not do this," unless a hard policy line is crossed.
How do we handle agents already running without approval?
Amnesty, then registration. Announce a window where anyone can declare an agent with no consequences. Several security leaders ran exactly this play in 2026, and the count always came back higher than the tooling showed.
Should we block AI tools until the approval process is ready?
Blocking buys less than it costs. Usage relocates to personal accounts and unmanaged devices, and you lose the visibility you had. Ship a rough approval path fast and improve it. A published bad process beats an unpublished good one.
How do we know if our approval criteria are working?
Watch two numbers: days from request to decision, and the count of agents that never came through the process at all. If the second keeps growing while the first stays high, your process isn't strict. It's being avoided.
Key takeaways
Security gets named the AI agent approver by default, then discovers nobody defined what approval means.
Committee-based approval in 2026 took months per use case, and the business routed around it to places with no logging.
Five written questions (identity, scope, data, failure response, owner) turn approval from a debate into a form.
Set autonomy against the quality of the answers, so approval becomes "how much" instead of "yes or no."
The argument that changes minds is time: an incident stops work for weeks, a criteria document stops one request for two days.
Want a baseline before you write the page? The free self assessment takes about four minutes and shows where your current approvals fall short.
The undefined word is the real problem. Until "approved" means something specific in your company, security will keep getting handed a decision it was never given the authority to make.