George Kavuma

Three signatures an agent can't skip.
Human approval in an AI dealer-sales platform.

7 months on the account. 3 human gates in the order flow. 9 days from kickoff to executive demo.

Role
Product Experience Lead, NextGen AI
Client
Confidential, global industrial technology company
Discipline
Workflow design, agent governance, interaction design
Team
7 developers across three countries, co-managed
Status
Executive demos delivered, August 2026
Year
February to September 2026
Internal approval card, human gate 1 of 3: waiting time, the rejection rule, and three stacked actions. Reconstruction with fictional data.
The decisionApprove, reject with a reason, or send it back to the agent. No configuration removes this gate.

The client wanted agents selling. I made every agent ask permission.

The situation

A global industrial technology company sells through independent dealers. Equipment goes out on multi-year leases, and software rides on the installed fleet. The client asked NextGen AI for AI agents inside that sales motion: quoting new solutions, and catching leases before they roll over. I led the product design.

The people who would run these agents are dealer reps and order desks, not engineers. Enterprise workflow, real money, no tolerance for a wrong send.

The problem

An agent that prices a deal or emails a customer can lose money and trust with one action. Dealers guard cost and margin from the manufacturer, and from customers, by contract. Nobody could yet say what an agent was allowed to do alone.

Two products were also tangled together: ordering new solutions, and turning over leases near their end date. Same dealer, same book, different rhythm.

The constraint

Nine days from kickoff to an executive demo, with the workflow confirmed by the client on day three. One small team, mid-release. And the confidentiality rules were contractual: a cost leak is a breach, not a bug.

What I tried first

A fresh interaction model for the leasing surface. It demoed well and taught badly: reps now carried two mental models for one job. I threw it away and rebuilt leasing on the selling book they already knew, one expandable row, evidence under the row.

I also sketched autonomy tiers, where a trusted agent sends low-risk email alone. That died on one question: who eats the wrong send?

The decision

Agents propose. The platform writes. People sign.

Every recommendation arrives through one gateway carrying its rationale, its confidence, and the version of the agent that made it. Three human gates sit in the order flow: internal approval, customer approval, dealer submit. No configuration removes them. And selection is never sending: choosing an option highlights it, a second labeled click preps the email.

What I refused

Any autonomy above recommend. Agents raise exceptions; they never resolve them.

Client-side masking of dealer cost. Four visibility scopes render on the server, default deny, and opening the cost view writes an audit event.

What I traded away

There is no separate rep role: cost visibility binds to the dealer role, so the wrong flag shows too much and the fix is process, not product. Order state advances when the dealer submits, not when fulfillment acknowledges, because the demo needed a visible beat. Both gaps are logged as risks with revisit triggers. Both are still open.

Seven months, not one sprint.

Month one, February

The order spine and the approval model. Quote generation, pricing rules, and role-based access on a real screen.

In between

The client took the prototype in house to build it themselves. Ten weeks later that effort stalled and they came back.

The nine-day sprint sits inside month seven, not in place of it.

Month seven, August

Selling and leasing on one interaction model, so a rep learns the job once.

Visibility scopes on the server, exceptions a person resolves, audit under every state change.

The real workflow, rebuilt with fictional data and a neutral brand.

Lease turnover book with an expanded row: agent rationale on the left, three suggested options on the right. Reconstruction with fictional data.
Lease turnover bookOne expandable row, evidence under the row, on the selling book reps already knew.
Quote screen with dealer-internal cost and margin beside the customer-safe view that has neither. Reconstruction with fictional data.
Visibility scopesCost and margin render server-side, per role. The customer response never contains them.
Suggested options card: the recommended option highlighted as selected, two alternatives below it, and separate Override and Prep customer email buttons. Reconstruction with fictional data.
Selection is not sendingChoosing an option highlights it. The customer email is a second, labeled step, and it opens as a draft a person signs.
Same quote in two visibility scopes: the dealer-internal table with cost and margin, and the customer-safe table with price only. Reconstruction with fictional data.
Two scopes, one quoteCost and margin exist only in the dealer projection. The customer response never carries them, because the server never sends them.
Order timeline with six status lamps and an append-only event log. Reconstruction with fictional data.
Order stateRound lamps carry state, a square lamp carries a fault, and the mock integration says so on its face.
Recommendation card: the agent's rationale, confidence, and version above one primary action. Reconstruction with fictional data.
Rationale, carriedEvery recommendation arrives with its reasoning, its confidence, and the version of the agent that argued for it.
Order state timeline with a square fault lamp on Integration ack, an exception raised to order entry, and Retry and Resolve actions. Reconstruction with fictional data.
Fault stateA square lamp carries the alarm. The agent raises the exception; a person resolves it and the resolution is logged.
Order spine diagram: ten states from discovery to licensing with three human gates marked. Reconstruction with fictional data.
Order spine, ten statesThree human gates no agent can cross, mapped before any screen was drawn.
Request to view
Walkthrough, vertical solutionRecorded on the working build, so it stays off the public page. Email me and I will share it.

What was delivered, and where it stands.

Delivered: the order spine end to end. Quote to license with three human gates, tokenized customer approval, and an append-only audit trail.

Delivered with it: the lease turnover book, on the same interaction model as the selling book reps already use.

The dealer portal was mine end to end. The leasing agent was a teammate's, and I designed the book it reports into.

Demo grade by design: connectors to the client's order and ERP systems ship as labeled adapters, not live integrations.

The client is confidential and is not named. Still screens are reconstructions with fictional companies, people, and prices; the walkthrough is recorded on the working build. The workflow, the rules, and the interaction decisions are the real ones.

Outcome.

Verified 7 months on the account. February to September 2026, the first approval model through to a unified selling and leasing build.
Verified 9 days. Kickoff Monday, workflow confirmed by the client Wednesday, executive demo the next week.
Client-confirmed 3 human gates. Internal approval, customer approval, dealer submit. No configuration removes them.
Delivered 3 products demoed. The dealer portal was mine. Leasing and live sales ran beside it on one shell.
Verified 15 decisions logged. Each with the alternatives it rejected and the trigger to revisit it.
Delivered 4 visibility scopes. Server-side projections, default deny. Dealer cost never reaches a client it shouldn't.
Delivered 10 states, discovery to license. Every transition writes an append-only event.
Verified 10 weeks. The client took the prototype in house to build it, stalled, and came back for the design.
Team 7 developers, 3 countries. Same platform team as the NextGen AI case, co-managed.
The Toronto skyline and CN Tower at dusk, seen from the harbour with an amber sunset.
Field note 08 · Toronto Harbour