Help center
Why you approve every change.
Nothing lands in your record without your click. Here is how the gate works, and why.
Nothing your AI proposes lands in your compliance record until you click to approve it. The approval gate is not a setting you can turn off, and it is not something your AI can work around. This article explains how the gate works, why it is built this way, and what your part in it is.
This works the same way for every framework Kanonik supports. It is about how a change reaches your record, not about any one standard.
Why a human approves every change
Your compliance record is only as good as its defensibility. When an auditor or a customer reviews it, the question behind every entry is the same: who stood behind this, and can you prove it. The approval gate answers that question for every change. A named person looked at the change and authorized it, and that act is recorded.
That is what keeps a human accountable for each entry. The AI does the drafting and the legwork, but it does not get to write to your record on its own. You do, by approving. This is what makes the record hold up later, rather than being a pile of changes no one signed for.
How approval works
A change moves through a fixed sequence, and you only enter at the end:
- Your AI prepares the change. It drafts the policy, the control, the mapping, or whatever you asked for, and submits it.
- The safety check runs first. An independent check runs on Kanonik's servers and reaches a verdict on the change. The approval link does not exist unless the change passed this check, so you are never handed something the check has not looked at.
- You get a single-use approval link. Kanonik creates a link tied to that one change.
- You open it and click. You see the change and what the safety check found, and you approve.
- The change is recorded. Only after your click is the change sealed into your audit log.
Approving records who approved, when, and against what the safety check found, in a tamper-evident audit log. That entry cannot be edited or removed afterward.
Why saying "yes" in the chat is not enough
You might tell your AI "yes, go ahead" in the conversation. That is not approval. A reply in a chat is easy to lose, easy to dispute, and tied to a session no one else can see.
The click is different. It is an act you take outside the conversation, on a link made for that one change, and it is written into your record as the moment of authorization. That separation is the point. The approval is a recorded act, not a line in a transcript, and that is what an auditor can rely on.
Single-use, short-lived links
Each approval link is good for one click and is short-lived on purpose. One link approves one change, and once you have used it, it is done.
If a link expires before you click it, nothing was lost. The change was never recorded, so there is nothing to undo. Ask your AI to send a fresh link and approve that one.
When you have several changes to approve at once, your AI can prepare them as a batch, and you approve the whole set in one click. The safety check still runs on every change in the set before the link is created. See Approving a batch of changes in one click.
Your role
Your job is to review and approve. You do not hand-edit the policies, controls, or other compliance objects yourself. That keeps the record clean: every entry traces back to a draft the AI prepared, a check that ran, and an approval you gave.
If a change is wrong, you do not fix it in place. You tell your AI what is wrong, and it prepares a new version that goes through the safety check again and comes back to you for a fresh approval. A rejected change goes back to your AI to redraft. The record only ever holds versions you approved.
More help
Browse every article in the Help center, where you can also ask the Kanonik assistant directly. For anything else, email support@kanonik.ai and a person who works on the product answers.