# Permissions decision worksheet

From Dryvn AI resources: https://www.dryvn.ca/resources/ai-approval-boundaries

## How to use it

Fill in one block per action the AI assistant or automation performs (or that you are considering). Sort each action into one of three categories: **Assistance only** (it reads, drafts, suggests; a person does everything with an effect), **Approved scope** (it acts on its own inside written limits), or **Specific human approval** (a named person approves each one). If you cannot fill in the owner, the limits and the revoke line, the honest category is Assistance only for now. Low impact does not grant authority. This worksheet is an educational tool from Dryvn; it is not a security control or a compliance framework.

## Blank worksheet

### Action 1

- Action:
- Category (Assistance only / Approved scope / Specific human approval):
- Owner (named person):
- Permitted data (records and fields):
- Limits (recipients, amounts, hours, frequency, stop conditions):
- Exception route (where out-of-scope items go, who reviews, when):
- Evidence (what is logged, where a person can read it):
- How permission is revoked (the switch, who can flip it, how fast):

### Action 2

- Action:
- Category:
- Owner:
- Permitted data:
- Limits:
- Exception route:
- Evidence:
- How permission is revoked:

### Action 3

- Action:
- Category:
- Owner:
- Permitted data:
- Limits:
- Exception route:
- Evidence:
- How permission is revoked:

### Action 4

- Action:
- Category:
- Owner:
- Permitted data:
- Limits:
- Exception route:
- Evidence:
- How permission is revoked:

## Review notes

- Date reviewed:
- Exceptions seen since last review:
- Scope changes agreed (and by whom):
- Revoke switch tested on (date):

---

## Fictional example (illustrative only)

A made-up two-person bookkeeping service. Names, figures and tools are invented.

### Action: send the first monthly receipt reminder by email

- Category: Approved scope
- Owner: Priya (owner)
- Permitted data: client name, client email, list of months with missing receipts, from the current-year client folder only
- Limits: only clients flagged "reminders OK"; only the standard reminder wording; once per client per month; weekdays 9:00 to 17:00 Pacific; stops for a client as soon as the client replies or asks to stop
- Exception route: any client not flagged, any bounce, and any reply lands in Priya's "reminders to check" folder; reviewed every Friday
- Evidence: the sent log (client, date, time, wording version) exported monthly to the client folder
- How permission is revoked: the "reminders" toggle in the assistant settings; Priya or her associate can switch it off; tested 2026-09 and confirmed sending stopped within the hour

### Action: tell a client their month-end books are complete

- Category: Specific human approval
- Owner: Priya
- Permitted data: not applicable; the assistant may draft, never send
- Limits: no automated sending; Priya signs off each month-end personally
- Exception route: not applicable
- Evidence: her sent email
- How permission is revoked: not granted
