Step 2 · Refine

Requirements, Permissions & Approval Design for Robo Claw at Large Banks and Financial Institutions

Once the target workflow is set, define the As-Is/To-Be picture, target departments, inputs and outputs, data classification, read/write permissions, dual approval, segregation of duties, accountability, boundaries of responsibility, logging, audit trails, and KPIs.

Bottom Line

The goal of the Refine step is to document exactly who automates the target workflow, how far that automation extends, and under what approvals. In particular, use this stage to nail down data classification and usage permissions for personal, credit, and transaction information; dual approval for any output that feeds into lending decisions or AML judgments; and segregation of duties across departments. Moving into the Pilot stage while these remain undefined will force a costly redesign later.

Who This Is For

Who This Is For

Written for IT/systems teams, risk management leads, compliance officers, and internal audit staff who have already selected a target workflow in the Discover step.

What You'll Decide

What You'll Decide in This Step

In the Refine step, you document the scope of the target workflow, the classification of the data involved, the systems it connects to, read/write permissions, approval conditions, segregation of duties, boundaries of responsibility, and KPIs — turning them into requirements that can be validated in Build & Validate.

Industry Challenges

Challenges Specific to Large Banks and Financial Institutions

01

Data classification is incomplete

In many cases, institutions haven't fully worked out which classification personal, credit, and transaction data fall into, or how far that data can be used.

02

Dual-approval rules aren't formalized

Rules on who provides dual approval for outputs that feed into lending decisions or AML judgments are often left unwritten.

03

Roles across departments are unclear

Operations often proceed without a clear division of responsibility among branches, head office, risk management, and compliance.

04

Accountability is undefined

It's often unclear who bears ultimate accountability for outcomes based on an AI agent's output.

Method

Implementation Steps

1. Map As-Is / To-Be

Compare the current workflow against the target workflow after Robo Claw is introduced.

2. Define target departments and workflows

Clarify which departments and which scope of work are in play.

3. Design the Agent, Skill, and Tool

Design the Agent's role, the Skill covering the workflow steps, and the scope of the Tool that performs system operations.

4. Confirm data classification

Work with legal and compliance to confirm whether input and output data qualifies as personal, credit, or transaction information.

5. Design Tool Policy and permissions

Define, as Policy, which operations the Tool may perform (read/write, Allow/Deny) and whether external transmission is permitted.

6. Define approvals and segregation of duties

Define who provides dual approval for outputs feeding into lending or AML decisions, and how duties are segregated across departments.

7. Define accountability and escalation

Define who is accountable for outcomes based on the output, and where exceptions should be escalated.

8. Define boundaries of responsibility, logging, audit trails, and KPIs

Define the boundaries of responsibility among the AI agent, the system, and people, along with the operation logs and audit trails to retain and the KPIs used to measure impact.

Data & Systems

Data and Systems Used

Internal policies & procedures Customer & credit information (within confirmed classification) Loan-related documents Access-permission registry Document management & workflow Permission & identity management systems

Human-in-the-loop

Where Human Approval Is Required

  • Define, by role, the dual approvers for output feeding into lending or AML decisions
  • Get legal and compliance sign-off on the scope of personal, credit, and transaction data being handled
  • Define the approver for output that involves sending anything to customers
  • Get IT sign-off on any cross-department permission grants

Measurement

KPI

In the Refine step, define candidate KPIs to be validated in Build & Validate.

Target initial-triage time

Target time for classifying an inquiry

Approval lead time

Time from output creation to human approval

Permission-violation detections

Number of detected operations that exceeded the defined permission scope

Checklist

Requirements-Definition Checklist

  • Target departments and tasks (in scope / out of scope) are documented
  • Input data and outputs (draft replies, draft materials, classification results) are defined
  • The classification of the data involved (personal, credit, transaction, etc.) has been confirmed
  • Read and write access permissions are defined separately
  • Dual-approval conditions and approvers are defined for output feeding into lending or AML decisions
  • Segregation of duties across departments is defined
  • Accountability for outcomes based on the output is defined
  • Escalation contacts and flow for exceptions are defined
  • Scope and retention period for operation logs and audit trails are defined
  • KPIs for measuring impact are defined

Pitfalls

Common Pitfalls

01

Skipping data-classification review

Proceeding without confirming data classification leads to major rework later around handling personal and credit information.

02

Leaving approvers vaguely defined

Naming approvers by individual rather than by role causes operations to stall when someone transfers or leaves.

03

Not documenting where the final decision sits

You need to document the division of responsibility clearly, so the AI's output is never treated as the final decision by default.

FAQ

Frequently Asked Questions

Which department should lead requirements definition?

We recommend joint leadership from the frontline owner of the target task and IT, with risk management, compliance, and legal also involved whenever personal data, credit information, or external transmission is involved.

How detailed should permission design be?

At minimum, define read/write scope by department and the dual approvers for output feeding into lending or AML decisions. Adjust the level of detail to the risk of the target task.

What is dual approval?

For high-impact decisions, it means requiring sign-off from multiple people in different roles, not just one approver. It exists to reduce the risk of mistakes or misuse.

Let's map out your requirements, permissions, and approval design together.

We can work out task scope, data classification, permissions, approval flow, and division of responsibility through a consultation on our official landing page.

Map Out Requirements, Permissions & Approvals