Foundry Academy · AI Workflow Training · Lesson 4 of 6

Human review and decision rights

Design review that is capable of detecting material failure and assign authority for approval, action, exception, and shutdown.

Start the lesson

Your learning work, on this device

No signup, cloud storage, cross-device sync or verified completion. Saving is optional. This browser profile is shared with anyone who can use it; private mode, browser cleanup or storage limits may remove work. Use only fictional or non-sensitive material. Export a copy before relying on this device.

Not saved. Worksheets, answers and practice notes currently last only in this tab.

Practice markers are self-reported, never credentials.

01 · Explanation

Human review and decision rights

Objective: Design review that is capable of detecting material failure and assign authority for approval, action, exception, and shutdown.

Human review is a control only when the reviewer has time, competence, context, authority, and evidence. Clicking approve after scanning a fluent answer is not meaningful oversight. Define what must be checked, against which sources or rules, at what sampling rate, and before which action. High-consequence outputs may require review of every case or separation of duties. Give reviewers an accessible view of inputs, relevant sources, model output, uncertainty, prior changes, and known limitations. Measure whether reviewers actually detect seeded defects; otherwise the workflow may create automation bias rather than safety.

A decision-rights matrix should name who prepares, reviews, approves, publishes, acts, investigates, and can pause the workflow. Avoid shared accountability that leaves nobody responsible. Reviewers must be able to reject output without penalty for slowing automation and must know when specialist expertise is required. Consider impacts on people who cannot challenge a result and provide a redress route where appropriate. When humans routinely rewrite most outputs or miss the same failure, change the workflow rather than blaming the reviewer. Document overrides and their reasons so patterns can reveal unclear instructions, data gaps, model limitations, or inappropriate task selection.

Before you begin

  • Confirm F02-F04 and F08-F10; record that approved routing labels, reviewer qualifications, sampling method, adjudication protocol, service level, and override log are absent.
  • STOP. If routing labels, reviewer qualifications, sampling, adjudication, service level, or override evidence is missing or conflicts with F02–F04/F08–F10, route the control to the accountable process owner and authorized human-review lead; do not claim review approval or execute routing, override, or production decisions.

Original overview module anchor →

02 · Compare the artifacts

Supported work. Visible uncertainty.

This is a fictional, sanitized AI-governance training case. All records are fabricated, and the exercise provides no legal, privacy, employment, medical, financial, security, or model-performance guarantee.

Redwood Assist governed intake workflow

Redwood Assist is a fictional services company considering an AI workflow to summarize new client intake and draft a routing recommendation. The current form receives about 420 submissions each month. It includes name, business email, phone, company, project description, budget range, requested timing, and an optional attachment. In a sample of 60 fabricated records, seven attachments contain government identifiers, four contain medical details unrelated to the service, nine include third-party personal information, and 16 lack enough context for reliable routing. The proposed model vendor offers a standard account with model-improvement use enabled by default and a 30-day content retention statement. No security, privacy, contract, data-location, deletion, or subprocessors review has been completed. A pilot prompt tells the model to identify serious founders and reject low-quality leads. The output labels applicants high, medium, or low potential, but neither potential nor serious is defined. In a 40-record test, the model routes 31 correctly according to one manager, while a second manager disagrees on 11 of those decisions. Two Spanish-language submissions are summarized with missing budget conditions. The team proposes automatically rejecting low-rated applicants and sending their attachment to a funding partner. There is no consent for partner disclosure, no human-review standard, no protected exception path, and no versioned evaluation set. Leadership wants the automation live next week to save eight hours of staff time. Learners must classify risk, constrain instructions and sources, establish data boundaries, design meaningful human review, build an evaluation set, and control exceptions and changes. The exercise cannot establish vendor suitability, lawful processing, fairness, or permission to automate decisions.

Supported example — reference only

Trigger
Managers disagree on 11 of 31 supposedly correct routing decisions — M04-I04 (F08).
Required reviewer competence
Authorized reviewer trained on the approved routing taxonomy; competence record not supplied.
Evidence presented
The disputed labeled records and manager decisions; record-level packet not supplied.
Allowed action
Adjudicate or abstain; do not enable automatic rejection.
Rationale record
Record selected label, cited evidence, uncertainty, reviewer role, and pending/decided state.
Adjudication
Independent qualified adjudicator required; identity and decision are not supplied.
Appeal
Reconsideration route not supplied.
Escalation
Accountable AI workflow owner and qualified risk reviewers.
Status
Draft — adjudication design pending

A well-handled evidence gap

Trigger
Two Spanish-language summaries omit budget conditions — M04-I05 (F09).
Required reviewer competence
Bilingual domain reviewer; assignment and qualification evidence not supplied.
Evidence presented
Two omission observations; source summaries and complete references are not supplied.
Allowed action
Hold consequential routing and request source-aligned bilingual review.
Rationale record
Required preservation of omitted condition and comparison evidence is a learner proposal.
Adjudication
Not supplied
Appeal
Not supplied
Escalation
Multilingual quality owner and accountable process owner.
Status
Blocked — review evidence not supplied

Flawed approach — do not copy

Marking this human-review standard “approved and complete” without the required evidence or reviewer is a flawed submission. Stop automated progression when a mandatory-review trigger, reviewer disagreement, material-language omission, or rejected appeal is unresolved.

Repair: Rework the human-review standard as an evidence-backed draft, not an approved result. Define which outcomes always require review: sensitive data, missing context, disputed labels, multilingual material terms, and proposed rejection. Specify the evidence the reviewer sees and what must remain masked or minimized. Define accept, correct, abstain, escalate, and reject-output actions without allowing silent override. Check the revision against this requirement: Review triggers, allowed actions, evidence view, override log, adjudication, and escalation are defined. If the required evidence is still absent, keep the decision blocked and identify the missing input or authorized reviewer.

Full case record, ambiguities and all assignments →

03 · Bounded practice

Build the human-review standard.

Define reviewer competence, evidence, authority, workload, and reject or escalate controls.

Deliverable: A human-review standard and two review-record starters: one for missing routing context and one for a Spanish-language condition omission, with unavailable source text and model output marked not supplied.

Complete a bounded starter and gap analysis using only CB01, F02, F03, F04, F08, F09, F10, and the assignment-scope record below. Populate supported fields, label every unavailable field “not supplied,” and cite the input ID for each material statement. You may design a proposed template, control, question, or decision rule, but must label it as a learner proposal rather than observed case evidence. Do not contact people, access live systems, run tests, sign records, claim approval, or invent names, dates, quotations, transactions, results, or source documents.

Exact supplied inputs for this assignment
  • M04-I01 · F02 — Seven of sixty fabricated attachments contain government identifiers.
  • M04-I02 · F03 — Four contain unrelated medical details and nine contain third-party personal information.
  • M04-I03 · F04 — Sixteen sampled records lack enough context for reliable routing.
  • M04-I04 · F08 — Managers disagree on eleven of thirty-one supposedly correct routing decisions.
  • M04-I05 · F09 — Two Spanish-language summaries omit budget conditions.
  • M04-I06 · F10 — The team proposes automatic rejection using the low-potential label.
  • M04-B01 · CB01 — Use CB01, the full versioned case brief printed once at the start of this packet, as a citable narrative source for details not normalized into F01–F12. Preserve its uncertainty language and do not treat narrative detail as approval, complete operational records, or professional judgment.
  • M04-S01 · F02, F03, F04, F08, F09, F10 — Build a starter version of “A human-review standard and two review-record starters: one for missing routing context and one for a Spanish-language condition omission, with unavailable source text and model output marked not supplied.” from the listed case facts. Treat requested structures, controls, questions, calculations, and templates as learner-designed proposals. Where an operational record or result is absent, add a gap entry naming the missing evidence and authorized owner instead of fabricating it.

Operating procedure

  1. Define which outcomes always require review: sensitive data, missing context, disputed labels, multilingual material terms, and proposed rejection.
  2. Specify the evidence the reviewer sees and what must remain masked or minimized.
  3. Define accept, correct, abstain, escalate, and reject-output actions without allowing silent override.
  4. Use F08 to require independent adjudication when reviewers disagree.
  5. Use F09 to require bilingual review of material-condition preservation.
  6. Set escalation and pause rules for critical failures and repeated disagreement.
  7. Final-QC for reviewer competence, traceability, conflict handling, appeal path, and pending authorization.
Field-by-field guidance
Trigger
Name an evidence-backed condition that requires human review and cite its input/fact ID.
Required reviewer competence
State the role capability needed; leave individual assignment or qualification evidence pending.
Evidence presented
List only the supplied records needed for review, with exact source IDs.
Allowed action
Define the bounded action a reviewer may take; do not imply approval or execution.
Rationale record
Specify the minimum decision rationale and source links to record.
Adjudication
State the independent disagreement-resolution path or Not supplied.
Appeal
State the proposed appeal/reconsideration path or Not supplied.
Escalation
Name the accountable or specialist route for unresolved risk.
Status
Use Draft, Pending adjudication, Blocked, or another truthful state.
Human-review standard · learning draft
TriggerRequired reviewer competenceEvidence presentedAllowed actionRationale recordAdjudicationAppealEscalationStatus

Start with 5 rows; the complete workbook specifies 5 stable rows for this artifact. Add rows here or use the full download. No action is saved until you explicitly choose saving above.

Download complete six-module workbook (.md) · Structured case packet (.json)

Keep private client data, unpublished inventions, personal identifiers and credentials out of these public learning tools.

Module 4 · 2-item formative check

Human review and decision rights

Choose an answer and request feedback. Read why each option does or does not fit the evidence. Answers stay in this tab unless you choose device-only saving; they are never submitted.

Question 1 of 2 · MODULE 4 · knowledgeWhen does a human review step become a meaningful operational control?
Question 2 of 2 · MODULE 4 · scenarioF02 and F03 confirm sensitive data, F04 confirms insufficient routing context, F08 is conflicting across manager decisions, F09 confirms Spanish omissions, and F10 is provisional for automatic rejection. Which review finding is actionable?

Answer either question to review its reasoning.

Inspect the artifact, not just your quiz answers

  • Review triggers, allowed actions, evidence view, override log, adjudication, and escalation are defined.
  • F08/F09 disputes shape the standard.
  • No review outcome or authorization is fabricated.

Stop: Stop automated progression when a mandatory-review trigger, reviewer disagreement, material-language omission, or rejected appeal is unresolved.

Go: Proceed only when a qualified reviewer can inspect evidence, correct output, record rationale, and halt the process.

Escalate: Escalate critical failures and unresolved adjudication to the accountable domain, privacy/legal, and model-risk owners.

04 · Evidence to keep

Leave with usable work.

Submit the review checklist, decision-rights matrix, seeded-defect results, override log, and escalation rule.

Download your artifact CSV and, if wanted, export the learning-work JSON above. Neither export is a reviewed submission or certificate. Device-only saving is optional; you must press Save my work now after edits.

When all six artifacts are ready, compare the full packet against the track rubric. Qualified human review is still required before real-world decisions.

Technology team discussing an AI-assisted workflow and its controls.
Learn the standard. Practice the work.
Professional reviewing an AI-assisted output on a laptop before approval.
Leave with evidence you can inspect.

Sources, scope and review boundaries

Curriculum 2026.10.08-learning-paths-1. External source dates below are record checks, not continuing guarantees. Verify current requirements before consequential use.

nist-ai-rmf · Official guidance

NIST Artificial Intelligence Risk Management Framework

Primary NIST resource for governing, mapping, measuring, and managing AI risk across the lifecycle.

Open reviewed external source ↗

nist-ai-600-1 · Official guidance

NIST AI 600-1: Generative Artificial Intelligence Profile

NIST's cross-sector profile describing generative-AI risks and actions aligned with AI RMF 1.0.

Open reviewed external source ↗

ws-ai-workflow-operating-standard · Academy internal operating standard

Wealth Synergy AI workflow internal operating standard

Academy-selected task classification, prompt, evidence, human-review, evaluation, exception, and change controls. This is an internal operating standard selected by Foundry Academy; it is not law, accreditation, licensure, or an external-standard requirement.

Version 1.0 · reviewed 2026-09-01 · owner: Foundry Academy curriculum owner

A future Wealth Synergy private professional-development certificate would be issued only after its assessment, capstone, identity, reviewer, retention, access, deletion, appeal, and issuance controls pass quality review. No credential is currently issued. Any future certificate would not be an accredited academic qualification, professional license, or government certification.