Review queues
Let AI organize applications while reserving restricted decisions for a person.
EU AI Act · Hiring & human oversight
Human oversight requires people to understand and intervene in high-risk AI operation. This hiring example shows a company reserving applicant rejection for a person while allowing AI to prepare the review queue.
Keep final hiring decisions with people when your policy requires human review.
These rejections stop here. The AI wants to reject three hundred and forty applicants, but its permission is limited to queuing them for review.
Think of it as letting an assistant organize the paperwork without giving them the final say.
This is just one example. Other workflows could cover review queues, interview invitations, or offer letters that need a person's approval.
HR leaders define the permissions. Integrations check before the hiring system acts. This browser illustration assesses no candidates and makes no hiring decisions.
01 · AI asks to act
Hiring workflow · 340 fictional applications
Requested action
Reject all 340 applicants
02 · Your rule applies
Ready to check. No request has been evaluated in this example yet.
An example permission policy. It does not assess candidates or certify EU AI Act compliance.
See the underlying technology: live rover demoYou keep your AI and existing systems. We start with one workflow, configure checks around your approved rules, and connect them where the AI tries to act. Authorized requests can proceed. Other requests stop, with a record explaining the decision.
Your Chief Human Resources Officer and Head of Talent Acquisition define which tasks AI may perform and which decisions require a person, working with legal and compliance leaders.
Your HR systems team connects the hiring workflow and its review queue.
Before the connected hiring system processes a restricted action. The integration must prevent the agent from going around the check.
We scope one workflow, translate supported rules into a versioned, validated, signed policy package, and connect an adapter that supplies trusted facts such as identity, recipient, and approval status. We then test allowed requests, blocked requests, and attempts to bypass the check before enabling execution.
One maintained kernel can support different policy packages and system adapters. A JSON file alone is not a complete deployment. We confirm rule support and integration requirements for your systems during scoping; additional implementation may be needed.
These are typical ownership patterns; responsibilities vary by organization.
The EU AI Act identifies recruitment and selection uses among its high-risk categories, subject to the Act’s classification rules. For high-risk systems, Article 14 addresses effective human oversight. Our example shows a company choosing to reserve rejection decisions for a person; it does not claim that this exact rule is required for every hiring system.
A versioned policy package can express supported controls chosen through your risk management process. It does not replace the risk assessment or the ongoing management process.
Real kernel receipts can help document requests and authorization decisions. Your organization must still establish the logging, retention, access, and documentation required for its system.
Permission checks can support a workflow that reserves actions for people. Effective oversight also depends on the people, authority, procedures, and system design around that workflow.
ExecLayer is an execution control component. This example is not a conformity assessment, legal advice, or certification of compliance. Your legal and compliance leaders determine the obligations and dates that apply to your specific use.