Step 2 · Refine

Requirements, Permission and Approval Design for NGOs Adopting Robo Claw in Meal Provision

Takes the target operations decided in the Discover step and makes them concrete down to: the scope of target programs, sites, event dates and provision formats; Agent, Skill, Tool and Tool Policy; classification of recipient, participant, guardian, health and allergy information; read/write permissions; separation from recipient and participant decisions; separation from food safety, allergen and provision-eligibility decisions; separation from donation, expenditure and compensation matters; approval of external transmission and SNS publication; connections to external SaaS, APIs and partner organizations; the division of responsibility between headquarters, sites, partner organizations and volunteers; logs and audit trails; prevention of duplicate execution, duplicate bookings, misdirected sends and misclosures; and KPIs.

Who This Is For

Who This Is For

Intended for meal-hall operations managers, food hygiene officers, personal information protection officers, and directors who have determined the target operations in the Discover step.

What You'll Decide

What You'll Decide in This Step

In the Refine step, you document the scope of target programs, sites, event dates and provision formats; the classification of data handled; the systems to connect to; read/write permissions; approval conditions; the division of responsibility between headquarters, sites, partner organizations and volunteers; and KPIs.

Industry Challenges

Challenges Specific to Meal-Provision Operations at NGOs and NPOs

01

Data classification is not sufficiently organized

In many cases, it is unclear which classification recipient information or health and allergy information belongs to, and how far it may be used.

02

Rules for the division of responsibility between headquarters, sites, partner organizations and volunteers are not in place

In some cases, the scope of information sharing and who the approvers are is not documented in partnership agreements or volunteer rules.

03

Roles between staff and volunteers are ambiguous

Operations sometimes run without a clear division of roles between full-time staff, part-time staff, and volunteers.

04

Where accountability lies is unclear

In some cases, who ultimately bears accountability for results based on AI agent output has not been worked out.

Method

Implementation Steps

1. Organize As-Is / To-Be

Compare and organize the current meal-provision operations flow against the operations flow targeted after Robo Claw is adopted.

2. Define target programs, sites, event dates and provision formats

Clarify the scope of target support programs, sites, event dates, and provision formats (meal hall, boxed-meal distribution, etc.).

3. Design Agent, Skill and Tool

Design the Agent's role needed for the target operations, the Skill for operational procedures, and the scope of the Tool that performs system operations.

4. Confirm handling of recipient, participant, guardian, health and allergy information

Organize the source, update method, and accuracy-verification method for each piece of information.

5. Confirm the purpose of use, legal basis, and guardian consent for personal and sensitive information

Confirm whether recipients' personal information and health information are handled, and confirm the purpose of use, individual consent, guardian consent, and legal basis.

6. Design Tool Policy and read/write permissions

Define, as Policy, the operations the Tool may perform (read/write, Allow/Deny) and whether external transmission and finalized publication are permitted.

7. Confirm separation of food safety, allergen, and provision-eligibility decisions

Confirm whether the design routes food safety, allergen-compliance, and provision-eligibility decisions through confirmation by specialist staff or a responsible person.

8. Confirm the division of responsibility between headquarters, sites, partner organizations and volunteers

Based on partnership agreements, confirm the scope of data sharing and the approval process with stakeholders.

9. Define human approval and responsible-person confirmation

Define who approves results based on output, and the escalation path to the responsible person when a recipient acceptance/rejection or provision-eligibility decision is required.

10. Define logs, retention period, duplicate-execution/duplicate-booking prevention and KPIs

Define the scope and retention period for operation logs and audit trails, measures to prevent duplicate execution and duplicate bookings, and measurement KPIs.

Data & Systems

Data and Systems Used

Participant and recipient information (classification-confirmed scope) Health and allergy information Site information and contact information Partner organization information and agreements Grant conditions and donor information Access permission ledger Booking/reception management system Permission and ID management system

Human-in-the-loop

Where Human Approval Is Required

  • Clarify, by role, who confirms output that leads to recipient acceptance/rejection, provision-eligibility, or food safety decisions
  • Obtain confirmation from the personal information protection officer and food hygiene officer for the scope handling personal information and health and allergy information
  • Clarify who approves output involving transmission to participants and donors, or publication on the web or SNS
  • Obtain the program manager's approval for permission grants spanning staff, volunteers and partner organizations

Measurement

KPI

In the Refine step, define candidate KPIs to be validated in Build & Validate.

Target level for initial inquiry-classification time

Target time for the initial classification of an inquiry

Lead time to approval

Time from output creation to human approval

Number of detected permission deviations / duplicate-booking candidates

Number of operations exceeding the defined permission scope, or detected duplicate-booking candidates

Checklist

Requirements-Definition Checklist

  • The scope of target programs, sites, event dates and provision formats (operations included and excluded) is documented
  • Input data and output (meal-count plan drafts, menu candidates, report drafts, etc.) are defined
  • The classification of data handled (recipient information, personal information, health and allergy information, etc.) and its purpose of use, individual consent, guardian consent, and legal basis are confirmed
  • Access permissions are defined separately for read and write
  • The division of responsibility (data-sharing scope, approval process) between headquarters, sites, partner organizations and volunteers is confirmed
  • Permission separation between staff, volunteers and partner organizations is defined
  • The escalation destinations and flow to the program, food safety, and personal information officers are defined
  • Where accountability lies for results based on output use is defined
  • The scope and retention period for operation logs and audit trails, and measures to prevent duplicate execution, duplicate bookings, and misclosures are defined
  • The KPIs used for measurement are defined

Pitfalls

Common Pitfalls

01

Skipping confirmation of data classification

Proceeding without confirming data classification later causes significant rework related to the handling of recipient information and health information.

02

Proceeding with the approver left ambiguous

Deciding the approver by individual name rather than by role becomes a cause of operations stalling during personnel transfers, resignations, or volunteer turnover.

03

Not documenting where the final decision lies

The division of responsibility must be documented so that operations do not end up treating AI output directly as a provision-eligibility or food safety decision.

FAQ

Frequently Asked Questions

Who should participate in requirements definition?

We recommend that, at a minimum, the meal-hall operations manager, food hygiene officer, personal information protection officer, and site manager participate. If allergy handling is required, confirmation by a specialist is also necessary.

What is Tool Policy?

It is a rule that documents the scope of operations a Tool may perform (read/write, whether external transmission is allowed, whether finalized publication processing is allowed, etc.). In Robo Claw, Tool Policy is designed per operation.

How finely should permission separation be designed?

At a minimum, we recommend separation across four categories: full-time staff, part-time staff, volunteers, and partner organizations. If the number of sites or event dates increases, also consider separation by site or by event date.

How should prevention of duplicate execution and duplicate bookings be designed?

Design a combination of execution IDs, idempotency checks, and a final human confirmation so that the same booking or report is not generated or sent multiple times. Details are explained in the Build & Validate and Deploy & Operate articles.

Let's work through the requirements, permission and approval design together.

You can confirm target programs, data classification, division of responsibility, and approval structure, and discuss requirements definition on the official landing page.

Talk to an Expert