Skip to content
redactsure
Book a demo

Explore.

Explainer · By Chris Sowa · Published
Last updated

Should an AI Agent Ever Have an "Always Allow" Setting?

Use standing permissions only for bounded, reviewed tasks. Consequential payments, submissions and record changes need the approval and evidence required by the workflow's policy; an unlimited waiver removes that checkpoint.

An open route continues past a standing permission dial while separate gated paths represent individual approvals.

Use standing permissions only for bounded, reviewed tasks. Consequential payments, submissions and record changes need the approval and evidence required by the workflow's policy; an unlimited waiver removes that checkpoint. A standing permission and approval of a particular payment answer different questions. Vendor agents combine permissions, automated review and mandatory confirmations in different ways. RedactSure's Supervised Delegation requires a named approver for consequential actions or an explicitly defined batch. That is a product control choice, not a claim that every cited regulation mandates manual approval of every action. RedactSure, an AI agent controls, governance and data protection company, applies Least Exposure and render-layer tokenization to this problem.

Key findings

What do the consumer and business agents ship?

From the vendors' own documentation and cited press, as of September 30, 2026.

Meta's Muse runs each user's agent in a dedicated Secure VM with a separate Sentinel that must approve every network egress. Sensitive actions such as sending an email or making a purchase stop for the user's approval. The user may set "always allow" for a class of action, per Meta's write-up. Muse for Small Business, launched September 29, extends the same agent to Shopify, Stripe, QuickBooks and the rest of a small business's tools. Help Net Security's coverage quotes the statement that "users remain in control, with nothing published, sent or spent without their approval."

OpenAI's Dots, launched the same day, use Custom Rules: the user sets what a dot may do on its own, what requires approval and what is forbidden. Sensitive operations such as password changes stay with the user, and Custom Rules cannot override mandatory confirmations. When the user is away, dots do "proactive research" in read-only mode. A separate Auto-review system checks planned actions against instructions, Custom Rules and safety requirements before execution. "If Auto-review blocks a step, it prevents the action from running and tells the dot why." An Activity View lets the user follow, redirect or stop work. The same document closes with "Dots can still make mistakes, so always review consequential work" (OpenAI). Enterprise, Edu and Healthcare workspaces can enable beta versions through administrator controls, per The Next Web.

Claude in Chrome offers two modes: "Automatically approve," the default, which pauses on actions the classifier judges risky, or "Manually approve" every action. Financial sites require permission, and organizations can set allowlists and blocklists (Claude Help Center). ChatGPT agent requires confirmation for high-impact actions and offers a "watch mode" on certain sites (OpenAI Help Center).

Each vendor built the same shape: a gate, a person who can be asked, and a setting that stops asking.

What is the difference between a permission and an approval?

A permission is standing and impersonal. It says that this class of action is allowed, for anyone or anything that holds the permission, until someone changes it. "Always allow" is a permission. A Custom Rule placing an action in the autonomous tier is a permission. An "Automatically approve" default is a permission. Once set, the person who set it is not present at the moment the action happens. That person may not be the one who would have judged this instance, and may have left the organization.

An approval is a named person, a specific action, a moment and a record. It says that on this date, this individual looked at this payment, this submission or this record change, and said yes. The approval carries the amount, the counterparty, the screen it was made from and the name. The organization can produce it afterward.

The two are not interchangeable in a regulated workflow. An audit may ask more than "was this class of action permitted." It is "who approved this one." A claims examiner asks who approved the payment on a specific claim. A privacy officer asks who authorized the disclosure on a specific chart. A school business manager asks who approved the budget transfer for a specific line. A controller asks who released the payment to a specific vendor. A standing permission answers all four with the name of whoever set the rule, months earlier, about a different action.

Why do the regulators ask for the approval?

The cited rules address different duties: appropriate use of PHI, documented AI governance, access controls and federal risk management. They do not collectively impose a universal manual approval requirement for every regulated action. HIPAA's minimum necessary standard, for example, supports policies for routine uses and has exceptions.

An organization should translate the applicable obligations into a workflow policy. That policy can distinguish a low-risk retrieval from a payment release, and can define when batch approval is appropriate. RedactSure's approach is to require a named approver for consequential actions and record that decision under Supervised Delegation.

Federal references must use M-25-21, which replaced M-24-10. The applicable agency policy and use classification determine the required review.

What does "consequential" mean in practice?

Payments, submissions, record changes and external messages. In insurance, releasing a claim payment or issuing a settlement letter. In healthcare, changing a chart, submitting a claim to a payer or sending a patient communication. In education, changing a student's record, transferring a budget line or sending a guardian a notice. In finance, releasing a vendor payment, changing a vendor's bank details or filing a return.

The amounts and thresholds are the workflow owner's to set. A claims manager may decide that any payment under a stated amount, matched to an approved reserve, can be batched for one review. Anything above it is approved one at a time. A school business manager may decide that transfers between lines in one department are low-consequence and transfers between departments are not. A named person still approves the batch, and each action in it lands on the record with the name. An unlimited waiver should not replace the risk assessment, documented thresholds and ongoing review.

What does Supervised Delegation record?

The policy, observed work and approvals needed to review the run. Under Supervised Delegation, a named person grants the access, chooses the applications, confirms what is tokenized, can watch and pause the run, and approves every consequential action. The AI Control Record holds every screen the agent saw, as tokens, every action it took, and every approval with a name, exported to the customer's own monitoring. When the claims examiner asks who approved the payment on CLAIMANT_001's claim, the record has the name, the amount, the screen and the time. When the privacy officer asks who authorized the chart change on PATIENT_001, the record has it. The agent prepared the work; the person approved it; the record shows both.

How do the three approval models compare?

Control "Always allow" (consumer pattern) Custom Rules tiers (Dots) Supervised Delegation (RedactSure)
Who is answerable for the action Whoever set the rule, about a class of action, at an earlier time Whoever wrote the rule for the autonomous tier; the user for the approval tier A named person, for this action
When approval is given Once, in advance, for the class In advance for autonomous actions; at the moment for the approval tier At the moment, per consequential action or per defined batch
What is recorded An activity log in the vendor's app Activity View in the vendor's app; Auto-review outcomes Every screen as tokens, every action, every approval with a name, exported to the customer's SIEM
What an auditor sees The rule and the log The rule, the log and the vendor's review The confirmed policy, the tokenized screens, the named approvals
What happens under a successful injection The action runs if the class is allowed Runs if the tier is autonomous and Auto-review passes it; otherwise the user is asked The action stops for a named person; the injection collected tokens

Where does RedactSure sit?

RedactSure has no "always allow." A named person approves every payment, submission and record change, and the approval lands on a record the organization owns. AI co-workers do real work across an organization's applications inside a governed environment: a claims platform, an EHR, a student information system, an ERP, and the payer portals and email around them. There is no per-application integration and no change to user permissions. Every sensitive value chosen by policy is replaced by a consistent token at the render layer before any model reads the screen. The Planner sets which values are tokenized and what the agent may do on each screen, and a named person confirms that policy before the run. The human operator can watch, pause and take over the same tokenized stream the agent sees.

What the organization avoids is the gap an examiner finds first: a consequential action with no one answerable for it. The workflow owner sets the thresholds and may allow a defined batch of low-consequence actions to be approved in one review. Each action in the batch still lands in the AI Control Record with the approver's name, exported to the customer's own SIEM. Prompt injection that succeeds against a RedactSure agent collects tokens, and the consequential action still stops for a named person. Regulated workflows on this design are in pilot.

Methodology and limitations

OMB M-25-21 rescinded and replaced M-24-10 on April 3, 2025. References to the earlier memo are historical; current federal review must use the replacement and applicable agency policy.

The HIPAA minimum necessary standard has exceptions, including certain treatment disclosures. Its application depends on the purpose and parties. Replacing direct identifiers does not by itself establish HIPAA de-identification or remove all PHI from the remaining context.

The vendor documents are Meta's Muse safety write-up (September 2026), OpenAI's Dots safety document (September 29, 2026), OpenAI's "ChatGPT agent" help article and Anthropic's Claude in Chrome help articles. All are cited with their dates. Press from The Next Web, Help Net Security, Latent Space and Tech Insider is cited as press. Regulation is cited from the text of 45 CFR 164.502(b), OMB M-25-21, the NAIC Model Bulletin and the PCI SSC scoping guidance. Case law and enforcement actions are not surveyed. All were read as of September 30, 2026.

No hands-on testing of Muse, Dots, ChatGPT agent or Claude in Chrome was performed; each approval setting is described as the vendor documents it. The METR finding on self-approving agents reaches the page through Latent Space's coverage; the underlying research was not read. Early tester accounts are anecdote from the same source. OpenAI refers to a system card and to Enterprise administrator controls that could differ from the launch material. The NAIC adoption count is Quarles & Brady's March 2025 figure. The claim payment, chart change, budget transfer and vendor payment examples describe record types, not any specific organization; no customer or prospect is described. Vendor settings change; the page carries its date and is revised when the documentation changes.

Whether an approval design satisfies the minimum necessary standard, the NAIC bulletin, PCI DSS or current federal AI policy belongs to the organization's counsel, examiner or compliance officer, not to this page.

We did not run the vendor products or capture their model requests. Workflow examples are analysis, and RedactSure behavior is described from its current design.

What the record shows

Use standing permissions only for bounded, reviewed tasks. Consequential payments, submissions and record changes need the approval and evidence required by the workflow's policy; an unlimited waiver removes that checkpoint. Pick a recent consequential action and trace its permission, approval and result. A useful record identifies who owned the policy and who approved the action or batch.

Frequently asked questions

What is the difference between a permission and an approval?

A permission is standing and impersonal: this class of action is allowed until someone changes the rule, and nobody is present when each instance runs. An approval is a named person, a specific action, a moment and a record: on this date, this individual looked at this payment or this record change and said yes. Which actions need individual approval depends on the workflow and applicable requirements.

Can approvals be batched?

Yes, where the policy says so. A named person can approve a set of similar low-consequence actions in one review, such as payments under a stated amount matched to approved reserves, or transfers within one department. Each action in the batch still lands on the record with the approver's name, the amount and the screen it came from. Batching changes how many approvals a person gives in a sitting; it does not remove the person or the record.

Who is accountable when an always-allowed action goes wrong?

Accountability remains with the deploying organization and the people assigned responsibility for its policy and operation. A standing rule may identify an owner without recording approval of each instance. Keep both the policy history and the action record, and use named approval where the workflow requires it.

Does the METR finding about agents self-approving apply?

Latent Space's coverage of DevDay cites METR research finding coding agents self-approving flagged actions. A standing permission is the setting under which self-approval has consequences, because there is no person between the flagged action and its execution. A named approval on each consequential action is intended to prevent the acting agent from releasing its own consequential action: the agent can prepare the payment and cannot release it.

Does Supervised Delegation slow the work?

It moves the person from doing the work to approving it. The agent prepares the match, the claim, the transfer or the payment on tokens. The person reviews and approves, one at a time for high-consequence actions and in a batch where the policy allows. The time saved depends on the workflow and the quality of the prepared work; no timing study is reported here.

Can the approval threshold change as evidence grows?

Yes. The AI Control Record shows, for each workflow, how many actions were prepared, how many were approved unchanged and how many were corrected. A workflow owner can raise the batch threshold for a class of action once the record supports it. Autonomy is earned on the record, in the organization's own monitoring, and the named person remains on every consequential action however wide the batch becomes.

Sources

Vendor documentation

  1. Meta AI Research, "How We Built Safety Into Muse: Security and Safety for AI Agents" (September 2026). https://research.meta.ai/blog/security-and-safety-for-ai-agents-our-approach-with-muse
  2. OpenAI, "How we build safety, security and privacy into dots" (September 29, 2026). https://openai.com/index/how-we-build-safety-security-and-privacy-into-dots/
  3. OpenAI Help Center, "ChatGPT agent." https://help.openai.com/en/articles/11752874-chatgpt-agent
  4. Claude Help Center, "Use Claude in Chrome safely." https://support.claude.com/en/articles/12902428-use-claude-in-chrome-safely
  5. Claude Help Center, "Claude in Chrome permissions guide." https://support.claude.com/en/articles/12902446-claude-in-chrome-permissions-guide

Regulation and standards

  1. 45 CFR 164.502(b), HIPAA minimum necessary standard. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.502
  2. NAIC, Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adoption map. https://content.naic.org/sites/default/files/legal-adoption-map-ai-model-bulletin.pdf
  3. PCI Security Standards Council, "Guidance for PCI DSS Scoping and Network Segmentation." https://www.pcisecuritystandards.org/documents/Guidance-PCI-DSS-Scoping-and-Segmentation_v1.pdf
  4. OMB Memorandum M-24-10, "Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence" (March 2024). https://www.whitehouse.gov/wp-content/uploads/2024/03/M-24-10-Advancing-Governance-Innovation-and-Risk-Management-for-Agency-Use-of-Artificial-Intelligence.pdf

Independent analysis and press

  1. The Next Web, "OpenAI launches dots, always-on AI agents with their own cloud computers" (September 29, 2026). https://thenextweb.com/news/openai-dots-always-on-ai-agents-cloud-computers-devday
  2. Help Net Security, "Meta gives small businesses an AI agent that knows their work" (September 29, 2026). https://www.helpnetsecurity.com/2026/09/29/meta-muse-for-small-business/
  3. Latent Space, "AINews: OpenAI DevDay 2026" (September 29, 2026). https://www.latent.space/p/ainews-openai-devday-2026-dots-61
  4. Tech Insider, "OpenAI Dots vs Meta Muse: 4,000-App Enterprise Agent" (2026). https://tech-insider.org/openai-dots-meta-muse-enterprise-agent-2026/
  5. Quarles & Brady, "Nearly Half of States Have Now Adopted NAIC Model Bulletin on Insurers' Use of AI" (March 2025). https://www.quarles.com/newsroom/publications/nearly-half-of-states-have-now-adopted-naic-model-bulletin-on-insurers-use-of-ai

RedactSure documents

  1. RedactSure, "Accountable AI and Workflow Governance" (2026). https://redactsure.com/blog/accountable-ai-and-workflow-governance/
  2. RedactSure, "The Two Gaps AI Agents Opened in Your Security Stack" (2026). https://redactsure.com/blog/two-gaps-ai-agents-opened-in-your-security-stack/
  3. RedactSure, "Secure AI That Crosses Every Silo" (2026). https://redactsure.com/blog/secure-ai-that-crosses-every-silo/
  4. RedactSure Research, "What Is Supervised Delegation?" (2026). https://redactsure.com/research/what-is-supervised-delegation
  5. RedactSure Research, "What Is Render-Layer Tokenization?" (2026). https://redactsure.com/research/what-is-render-layer-tokenization
  6. RedactSure Research, "What Is an AI Control Record?" (2026). https://redactsure.com/research/what-is-an-ai-control-record
  7. RedactSure Research, "What Does Prompt Injection Get From a Token-Only Agent?" (2026). https://redactsure.com/research/prompt-injection-agent-sees-only-tokens
  8. RedactSure Research, "Can an AI Agent Work Guidewire Claims Without PII?" (2026). https://redactsure.com/research/ai-agent-claims-guidewire-pii
  9. Product behavior described on this page reflects RedactSure's current design. Meta and Muse are trademarks of Meta Platforms, Inc.; OpenAI, ChatGPT and Dots are trademarks of OpenAI; Claude is a trademark of Anthropic, PBC; named to identify the products. Compliance determinations belong to the organization's counsel.

Editorial verification

  1. Office of Management and Budget, Memorandum M-25-21 (April 3, 2025), current federal AI policy replacing M-24-10. https://www.whitehouse.gov/wp-content/uploads/2025/02/M-25-21-Accelerating-Federal-Use-of-AI-through-Innovation-Governance-and-Public-Trust.pdf

See it on your workflow.

Bring one billing, collections, claims or patient-account workflow and your questions.

Book a demo

Book a demo

Having trouble? Open the booking page or email us.