Skip to content

Grant approval authority only with evidence.

Poppelo starts with auto-approval off by default. Confidence-based routing stays subject to validation, tenant settings, customer policy, and restrictions that can reduce automatic approval authority.

Tenant permission is the starting gate

A tenant must explicitly enable auto-approval. Confidence thresholds can route records toward approval, review, or rejection, but they cannot bypass validation or policy gates. A downgrade-only restriction can move a record toward more review; it cannot promote an uncertain record into automatic approval.

Customer trust has its own controls

Per-customer autonomy is implemented behind feature flags, with sender verification, grant and revoke controls, anomaly checks, and synchronous demotion. Tenant auto-approval remains an additional requirement. These controls are intended to restrict eligibility as evidence changes, rather than treat every buyer alike.

Shadow evidence comes before rollout

Shadow mode provides a way to examine proposed autonomy decisions before granting authority. The autonomy flags are off when absent, production enablement is unverified, and no real-traffic shadow outcome is recorded in the capability ledger. Do not assume these flagged customer controls are enabled in a workspace; confirm rollout status with Poppelo.

Questions about this workflow

Does high confidence override customer restrictions?

No. Confidence-based routing remains subordinate to validation, tenant permission, customer policy, and downgrade-only restrictions.