Worksheet

Approval-record scoring worksheet

Score five real approval records out of four. The interesting number is not the total — it is which question fails across the set.

Why it exists

This does not measure whether you have approvals. You do; everybody does. It measures whether an approval you already collected can answer 'who authorized this?' about a specific action, months later, to someone not inclined to be generous. A human genuinely approved something and an action genuinely happened — the question is whether the record binds the second to the first. Take the five most recent records, or five at random from the last quarter. Not your best five; that defeats the exercise.

What it contains

01

Four questions, one point each, applied to five real approval records

02

The distinction between naming an account and naming a principal

03

Why a stated boundary is the load-bearing question, and the one that fails most often

04

The difference between an expiry field and an annual review meeting

05

How to read the result by column rather than by row

No email required, and nothing is recorded when you download. Use it, adapt it, argue with it — attribution is welcome, not a condition.

Worksheet · v1.0 · 23 August 2026

The four questions

Each is worth one point. Score five records. A single record scoring 2/4 tells you about one record; a column that fails five times out of five tells you about your system.

QuestionPasses whenFails whenThe common failure
1. Does the record name the principal?It identifies who or what acted in a way that distinguishes it from anything else that could have acted — a specific service identity, a specific human, a specific delegation between them.It names a shared service account, a role, a team or an integration. If four things in your estate could have produced this record, it does not name a principal.An agent runs under a service account that predates it, shared with two batch jobs and a monitoring integration. The record is honest and useless.
2. Does the record name the specific action?It describes the action at the granularity a person would need to decide whether it was acceptable — which record changed, which payment released, which customer contacted.It names a capability, a category or a workflow. 'Agent executed customer-update workflow' tells you a class of thing happened.The test: could someone who was not there tell you whether the action was the right one? If they would have to go and find out what actually happened, it is a category.
3. Does the record state the boundary of what was approved?It states what the approval does not cover — an amount ceiling, a set of accounts, a time window, a class of counterparty, a required condition.It records assent without extent. Someone approved; what they approved is inferred from context that is no longer available.An approval without a stated boundary expands to fit whatever the system later does under it. Nobody decides to widen it — there was never an edge to widen.
4. Does the record state when it expires?The approval has an end: a timestamp, a run count, a terminating condition, or a review date with teeth.The approval is standing, or its expiry is a policy statement elsewhere rather than a field on the record.If the system stopped honoring this approval tomorrow, would anything break that should not? If yes, 'we review those annually' describes a meeting, not a control.

Reading the columns

Read the columns, not the rows. The column that fails across the set is the finding worth having.

Column that fails across the setWhat it meansWhat to do about it
Q1 — principalYou have an identity problem, not an approval problem.Fixing the approval format will not help until agents have principals. Run the reachability audit first.
Q2 — actionYour logging granularity sits above your decision granularity.The approvals may be fine and you cannot demonstrate it. Raise the record, not the policy.
Q3 — boundaryThe common case: approvals record assent without extent.Add a stated boundary to the record format before adding anything else.
Q4 — expiryYou have standing authority nobody re-decides.Pair with the time-to-safe-state protocol — standing authority and slow revocation compound.

How to use it

  1. Pull five approval records. The five most recent, or five at random from the last quarter — not your best five.
  2. Score each against the four questions. About fifteen minutes per record once you have found them, and finding them is often the first finding.
  3. Read the result by column. One record scoring badly is a record; a column failing five times is an architecture.
  4. Do not expect 20/20. Very few production estates score above 2/4 on a random sample, and a team scoring 1/4 that knows which column failed is in better shape than a team that has never counted.
  5. Remember what it does not measure: it scores the record, not the decision. A record can pass all four and describe an approval that was substantively wrong.

Built from public standards and general practice. The instruments cited in this artifact are checked against their primary sources on an ongoing basis. Instruments move — several cited here changed inside the last year — so verify against the source before you rely on one. If you find something stale, tell me and I will correct it.

Related: the other artifacts · the diagnostic.

Next step

Want this applied to your estate?

These artifacts are general by design — and they are the method behind the Agent Estate Review: two to three weeks establishing what is actually running, what each thing is permitted to do, and where you could not evidence it if you were asked next week. You have just read how it works.