surehand
All articlesGovernance

OpenAI is training agents to build approval workflows. Treat a rule change like a payment.

News4 min readSurehand

OpenAI is now training agents to build approval workflows, not just to pass through them. That moves the most sensitive object in your company, the rule that says who signs off on what, into the agent's reach. If an agent can edit that rule, the edit itself needs an approver, and it should never be the person who asked for it.

On 6 October OpenAI described its first research partnership with Ironclad, the contracting software company1. Together they built 11 tasks across legal, commercial and procurement work. One of them is the kind of thing a legal ops team does: set up a process for buying software, where Finance approves purchases above an amount, Security reviews some requests and Legal reviews nonstandard terms1.

OpenAI is plain about what the agent has to get right. It "must configure Finance approval above the spending threshold and check that requests above and below it follow the right paths"1. GPT-6 Astra is the first OpenAI frontier model trained on Ironclad tasks1.

The numbers say "better", not "done"

Each task was graded against 8 to 50 criteria1. Across the 11 tasks, Astra's average score was 55.0%. GPT-5.6 Sol scored 41.6%. Estimated time per attempt fell from 37.0 minutes to 19.21. An internal model reached 63.7%1.

That is real progress. Read it the other way too. On OpenAI's own research evaluation, the newest model's average score is just over half.

The showcase run is more telling. On one task, Astra met about 94% of the criteria in an estimated 20 minutes1. That is the clip OpenAI put on its own page. About 6% of the criteria were still not met.

Now put yourself in the approver's seat. Which 6%? A wrong label on an intake form costs you nothing. A Finance threshold set one zero too high means every purchase under it skips Finance. Nobody gets an alert, because the workflow did exactly what it was configured to do.

OpenAI says the same thing in its own words: "If an agent loses track of one of those rules halfway through a task, that limits what a software company can confidently ask it to do"1. It adds that this "underscores why human oversight still matters"1.

Why this is a different kind of risk

Most agent controls assume the agent acts inside the rules. It pays an invoice, and the rule holds anything over the limit. You review the payment.

Here the agent writes the rules. A bad payment is one bad payment. A bad rule is every payment after it, until someone looks. And because the rule is valid configuration, your logs will show a clean, approved process.

This is old accounting logic. The person who can change the approval matrix shouldn't also run transactions through it. Segregation of duties for AI agents walks through how to map that split onto an agent. It matters more now that the agent is getting good at the setup work.

What to do this week

1. Find every place an agent can edit a rule. Not just contracting tools. Approval chains in your procurement system, spend limits in your card platform, routing rules in your ticketing tool, auto-approve thresholds in AP. If a service account an agent uses has admin rights there, write it down.

2. Make a rule change a held action. Treat "change Finance threshold from 25,000 to 250,000" the way you'd treat a 250,000 payment. It waits for one named person. That person is not the one who asked the agent to make the change. The two-person rule explains why the second person has to be a different person.

3. Show the approver the diff, not the summary. "Set up procurement workflow per requirements" is not reviewable. "Finance approval: above 25,000. Security review: SaaS vendors only. Legal: nonstandard terms" is. Old value, new value, side by side.

4. Test both sides of every threshold. OpenAI's own check is the right one: run a request just above the line and one just below, and confirm each takes the right path1. Do it before the rule goes live. Do it again after any agent edit.

5. Keep the rules file outside the agent's write access. The agent can draft a rule. It shouldn't be able to make it live.

What changes

Until now, the question was whether your agent stays inside the approval policy. OpenAI is now inviting more software companies to bring it tasks like this1. Expect agents to get steadily better at admin screens. The new question is who approves a change to the policy itself.

That is the job of a control plane. In Gatehouse, each action is checked against a signed rules file before it runs. Anything outside it is refused, or held for one named approver. Every decision lands in the record.

Start with step 1. Pick one system where an agent holds admin rights and list what it could change today. If you want a second pair of eyes on it, book a teardown.

Sources

  1. [1]OpenAI, Advancing computer use with Ironclad (6 October 2026)openai.com In text

Want the next one? News with a take, three times a week. Follow by RSS

Read next

[ your next step ]

Bring us the queue nobody wants.

One process, studied in writing. You keep the document, whatever it says.

support@surehand.io