Human-in-the-Loop Approval Authority Design Prompt
Design the decision-authority model for human-in-the-loop automation — who may approve which action tier, when two-person review or quorum is required, how approvers get the context to decide well, and how break-glass and timeouts work without weakening the controls.
- Target user
- Platform and security engineers governing automated change approval
- Difficulty
- Advanced
- Tools
- Claude, ChatGPT
The prompt
You are a platform engineer who designs the approval layer that sits between automation and production change. A good approval model gives the right person enough context to say yes or no quickly — and makes a rubber-stamp impossible for the riskiest actions. I will provide: - The actions automation can request and their risk/blast-radius tiers - Our roles and who currently has authority over what - The channels approvals happen in (ChatOps, ticketing, CI) - Compliance/separation-of-duties requirements and break-glass needs Your tasks: 1. **Authority matrix** — map each action tier to who may approve it. Specify where a single approver suffices and where two-person review or quorum is mandatory (and that the requester cannot self-approve). 2. **Decision context** — define exactly what each approver must see before approving: the diff/preview, blast radius, current state, who requested it, and the read-only pre-flight result. 3. **Timeout and escalation** — set how long a request stays open, what auto-deny on timeout looks like, and how it escalates if the first approver is unavailable. 4. **Separation of duties** — enforce that the person who built/triggered a change is not the sole approver of its production application, where compliance requires it. 5. **Break-glass** — design an emergency path that bypasses normal approval, but logs loudly, notifies broadly, and forces a retrospective review afterward. 6. **Tamper-evident audit** — record requester, approver(s), the exact context shown, decision, and timestamp, in an append-only trail. Output as: (a) the action-tier × approver authority matrix, (b) the required decision-context checklist per tier, (c) the timeout/escalation rules, (d) the break-glass procedure and its mandatory after-action, (e) the audit record schema. Reject any model that permits self-approval of production changes, that approves without showing the diff, or that has a break-glass path with no logging or review.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Automation Human-in-the-Loop Escalation Routing Prompt
Design when and how an automated workflow should pause and hand off to a human — defining confidence thresholds, escalation triggers, the notification path, and the timeout fallback so automation asks for help instead of guessing or stalling silently.
-
Break-Glass Privileged Access Workflow Design Prompt
Design a just-in-time, audited break-glass procedure for emergency privileged access — time-boxed elevation, approval, full session recording, and automatic revocation — so admins aren't sitting on standing root.
-
Self-Service Automation Catalog Portal Design Prompt
Design a self-service catalog that lets engineers safely run curated automation jobs on demand, with parameter validation, RBAC, approvals for risky actions, and an audit trail, without handing out raw runbook access.
-
ChatOps Approval Bot Design Prompt
Design a Slack/Teams ChatOps bot that safely runs ops commands with inline approvals — identity, authorization, four-eyes for risky actions, audit, and abuse resistance.
More Automation prompts & error guides
Browse every Automation prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.