detections
- ID: SDT032
- Created: 26th August 2026
- Updated: 26th August 2026
- Contributors: Nimer Kees, Yonatan Machluf, The ITM Team,
Human Approval Gate Effectiveness Monitoring
Human approval gate effectiveness monitoring treats the approval gate as the monitored object. The detection tests whether human review is actually constraining synthetic subject action, or whether approvals are rubber-stamped, bypassed, or gradually displaced by autonomous execution.
Implementation
Collect approval workflow logs, reviewer decisions, approval timestamps, request metadata, task risk level, action type, tool-call records, synthetic subject session records, non-human identity activity, and downstream system events. Each approval request should record the synthetic subject, requester, bound human principal, reviewer, action requested, target asset, risk classification, supporting evidence shown to the reviewer, approval decision, decision latency, and execution result.
Build reviewer and workflow baselines for approval rate, rejection rate, modification rate, escalation rate, decision latency, action type, risk tier, and review workload. Alert when approval rates approach automatic approval, when high-risk requests receive near-instant approval, when the same reviewer approves large volumes without meaningful latency, or when approved actions repeatedly lack reviewer-visible evidence sufficient to support the decision.
Track the ratio of autonomous to supervised actions for each synthetic subject, workflow, tool, and action class. Apply User and Entity Behavior Analytics (UEBA) to detect oversight thinning, such as a rising share of autonomous actions, declining approval latency, falling escalation rates, or a shift from reviewed to unreviewed execution without an approved policy or configuration change.
Detect gate bypass separately from rubber-stamping. Correlate downstream actions against approval workflow records and alert when a high-impact action executes without a matching approval event. For finance workflows, alert when transfers, refund approvals, beneficiary changes, payment instructions, or invoice actions skip the structured approval channel entirely, even if they were technically performed by an authorized identity.
Investigative Use
This detection supports investigation of autonomous action control failure, erroneous autonomous action, AI-mediated financial loss, destructive system or data action, and oversight erosion. It helps investigators determine whether a human approval gate was present, whether it was exercised meaningfully, whether it was bypassed, and whether supervision weakened over time.
It is especially useful where logs show human approval, but timing, approval rate, missing evidence, or downstream execution patterns indicate that the approval record provided little or no real control.