Requirements, Permissions, and Approval Design When an NGO Introduces Robo Claw
Concrete definitions are made for the target operations determined by Discover STEP, the scope of target projects, regions, languages, and digital channels, classification of Agents, Skills, Tools, and Tool Policies, classification of supporters, donors, beneficiaries, and volunteers’ information, read/write permissions, separation from support, grant, and safety judgments, separation from donations, expenditures, and remittances, approvals for external publication and transmission, responsibility allocation among headquarters, local sites, contractors, and volunteers, log and audit trails, prevention of double execution, duplicate transmission, and erroneous publication, and KPIs.
Who This Is For
Who This Is For
Targeted at business managers, personnel who also handle information systems, personal information protection officers, and directors who have determined the target operations in Discover STEP.
What You'll Decide
What You'll Decide in This Step
In Refine STEP, document the scope of target businesses, regions, languages, digital channels, the classification of data handled, connected systems, read/write permissions, approval conditions, the division of responsibilities among headquarters, local offices, contractors, and volunteers, and KPIs.
Industry Challenges
Issues specific to NGOs/NPOs
Insufficient organization of data classification
There are many cases where it has not been clarified which classification support recipient information and minor information belong to, and how far it can be used.
Rules for the division of responsibilities between headquarters, local offices, contractors, and volunteers are not established
There are cases where the scope of information sharing and approvers of reports in outsourcing contracts or volunteer agreements are not clearly documented.
Roles of staff and volunteers are unclear
There are cases where operations are being conducted without clearly defined roles for full-time employees, part-time staff, and volunteers.
Accountability is unclear
In some cases, it is not clarified who bears the final accountability for results that utilize outputs from AI agents.
Method
Implementation Steps
1. Organize As-Is/To-Be
Compare and organize the current digital business flow with the targeted business flow after the introduction of Robo Claw.
2. Define the target business, region, language, and digital channels
Clarify the scope of target businesses, regions, languages, and the digital channels to be used (email, SNS, forms, etc.).
3. Design Agents, Skills, and Tools
Design the roles of Agents required for the target tasks, the Skills for business procedures, and the scope of Tools for system operations.
4. Confirm the handling of supporter, donor, beneficiary, and volunteer information
Organize the sources of input, update methods, and verification methods for the accuracy of each piece of information.
5. Confirm the purpose of use and legal basis for personal and sensitive information
Confirm whether personal information and sensitive information of beneficiaries are handled, and check the purpose of use, consent of the individual, and legal basis.
6. Design Tool Policy and read/write permissions
Define as a policy the operations that the Tool is allowed to perform (read/write, Allow/Deny) and whether external transmission or publication is permitted.
7. Confirm the division of responsibility between headquarters, local sites, and contractors
Based on the contract specifications and agreements, confirm with stakeholders the data sharing scope and approval process for reports.
8. Define separation of authority for staff, volunteers, and local staff
Separate access permissions for full-time staff, part-time staff, volunteers, and local staff.
9. Define human approval and responsible person verification
Define approvers for results obtained using outputs and escalation points to responsible individuals in cases requiring approval or denial of support for beneficiaries, grant decisions, or safety judgments.
10. Define logs, retention periods, prevention of duplicate execution/duplicate transmission, and KPIs
Define the scope and retention period for operation logs and audit trails, measures to prevent duplicate execution/duplicate transmission, and performance measurement KPIs.
Data & Systems
Data and Systems Used
Human-in-the-loop
Where Human Approval Is Required
- Clearly define the reviewers for outputs that lead to decisions on acceptance of support recipients, grant eligibility, and safety, by role
- Obtain confirmation from the personal information protection officer and legal department regarding the scope of handling personal and sensitive information
- Clearly define approvers for outputs that involve sending to supporters, donors, and beneficiaries, or publication on websites and social media
- Obtain approval from the project manager for cross-authorization involving staff, volunteers, and local staff
Measurement
KPI
In the Refine STEP, define candidate KPIs to be verified in Build & Validate
Target level for primary classification time of inquiries
Target time required for primary classification of inquiries
Lead time until approval
Time from output creation to human approval
Number of detected cases of authority deviations or duplicate transmission candidates
Number of detected operations exceeding the defined authority scope or duplicate transmission candidates
Checklist
Requirements definition checklist
- Documented target projects, regions, languages, and digital channels (including or excluding business operations)
- Defined input data and output (draft responses, draft reports, draft posts)
- Confirmed classification of handled data (support recipient information, personal information, sensitive information, etc.), purpose of use, consent of the individual, and legal basis
- Access rights for reading and writing are defined separately
- The boundaries of responsibility between headquarters, local offices, contractors, and volunteers (scope of data sharing and reporting approval process) have been confirmed.
- The separation of authority between staff, volunteers, and local staff has been defined.
- The escalation destinations and flow to business, safety, and personal information responsible persons have been defined.
- Responsibility for explaining the use of outputs is defined
- The scope and retention period of operation logs and audit trails, as well as measures to prevent double execution, duplicate transmission, and accidental disclosure, have been defined.
- KPIs used for effect measurement are defined
Pitfalls
Common Pitfalls
Omit checking data classification
If you proceed without confirming data classification, significant rework related to handling beneficiary information and personal information will occur later.
Proceed with the approver unclear
If approvers are decided by individual names rather than positions, operations may stop when there are personnel transfers, resignations, or volunteer replacements.
Do not specify the location of the final decision in writing
It is necessary to explicitly define responsibilities to prevent operations where AI output is treated directly as a decision on beneficiary acceptance or grant eligibility.
FAQ
Frequently Asked Questions
Who should participate in requirement definition?
We recommend that the business owner, the person in charge of information systems concurrently, the personal information protection officer, and the local manager participate at a minimum. If handling sensitive information, confirmation by legal or specialists is also necessary.
What is a Tool Policy?
It is a documented rule defining the scope of operations that a Tool is allowed to execute (read/write, permission for external transmission, permission for final publication processing, etc.). In Robo Claw, a Tool Policy is designed for each business task.
How finely should the separation of authority be designed?
At a minimum, we recommend separating into four categories: full-time staff, part-time staff, volunteers, and local staff. If the number of regions or languages increases, consider separation by region or language as well.
How should we design to prevent double execution or duplicate sending?
To ensure that the same reply or report is not generated or sent multiple times, design using a combination of execution ID, idempotency checks, and final human verification. Detailed explanations can be found in the Build & Validate and Deploy & Operate articles.
Shall we organize requirements, authorities, and approval design together?
You can confirm the target projects, data classification, responsibility boundaries, and approval systems, and consult with requirements definition through the official LP.