Three signatures an agent can't skip.
Human approval in an AI dealer-sales platform.
7 months on the account. 3 human gates in the order flow. 9 days from kickoff to executive demo.

The client wanted agents selling. I made every agent ask permission.
A global industrial technology company sells through independent dealers. Equipment goes out on multi-year leases, and software rides on the installed fleet. The client asked NextGen AI for AI agents inside that sales motion: quoting new solutions, and catching leases before they roll over. I led the product design.
The people who would run these agents are dealer reps and order desks, not engineers. Enterprise workflow, real money, no tolerance for a wrong send.
An agent that prices a deal or emails a customer can lose money and trust with one action. Dealers guard cost and margin from the manufacturer, and from customers, by contract. Nobody could yet say what an agent was allowed to do alone.
Two products were also tangled together: ordering new solutions, and turning over leases near their end date. Same dealer, same book, different rhythm.
Nine days from kickoff to an executive demo, with the workflow confirmed by the client on day three. One small team, mid-release. And the confidentiality rules were contractual: a cost leak is a breach, not a bug.
A fresh interaction model for the leasing surface. It demoed well and taught badly: reps now carried two mental models for one job. I threw it away and rebuilt leasing on the selling book they already knew, one expandable row, evidence under the row.
I also sketched autonomy tiers, where a trusted agent sends low-risk email alone. That died on one question: who eats the wrong send?
Agents propose. The platform writes. People sign.
Every recommendation arrives through one gateway carrying its rationale, its confidence, and the version of the agent that made it. Three human gates sit in the order flow: internal approval, customer approval, dealer submit. No configuration removes them. And selection is never sending: choosing an option highlights it, a second labeled click preps the email.
Any autonomy above recommend. Agents raise exceptions; they never resolve them.
Client-side masking of dealer cost. Four visibility scopes render on the server, default deny, and opening the cost view writes an audit event.
There is no separate rep role: cost visibility binds to the dealer role, so the wrong flag shows too much and the fix is process, not product. Order state advances when the dealer submits, not when fulfillment acknowledges, because the demo needed a visible beat. Both gaps are logged as risks with revisit triggers. Both are still open.
Seven months, not one sprint.
The order spine and the approval model. Quote generation, pricing rules, and role-based access on a real screen.
The client took the prototype in house to build it themselves. Ten weeks later that effort stalled and they came back.
The nine-day sprint sits inside month seven, not in place of it.
Selling and leasing on one interaction model, so a rep learns the job once.
Visibility scopes on the server, exceptions a person resolves, audit under every state change.
The real workflow, rebuilt with fictional data and a neutral brand.








What was delivered, and where it stands.
Delivered: the order spine end to end. Quote to license with three human gates, tokenized customer approval, and an append-only audit trail.
Delivered with it: the lease turnover book, on the same interaction model as the selling book reps already use.
The dealer portal was mine end to end. The leasing agent was a teammate's, and I designed the book it reports into.
Demo grade by design: connectors to the client's order and ERP systems ship as labeled adapters, not live integrations.
The client is confidential and is not named. Still screens are reconstructions with fictional companies, people, and prices; the walkthrough is recorded on the working build. The workflow, the rules, and the interaction decisions are the real ones.
Outcome.
