Public or no institutional data
Evidence: use description, tool name
Santa Fe College
AI Approval WorkflowReviewer Reference
Trace how request conditions route into a likely risk tier, reviewer group, and decision range.
Routing Graph
Each flow shows the trigger, the likely tier, who joins the review, and the decisions that usually stay on the table.
Evidence: use description, tool name
Evidence: business purpose, data elements, human review plan
Evidence: data elements, minimum necessary rationale, security evidence
Evidence: full risk assessment, exception rationale, security controls
Evidence: data elements, sample records or description
Evidence: contract or terms, privacy policy, security documentation
Evidence: integration method, api scopes, authentication method
Evidence: ferpa purpose, student record elements, access controls
Evidence: impact assessment, human oversight plan, appeal or override path
Evidence: tool permissions, action boundaries, human approval gates
Evidence: tool permissions, approved tools list, action boundaries
Evidence: action inventory, human approval gates, rollback plan
Evidence: execution environment, sandboxing controls, secrets handling
Evidence: workflow description, trigger conditions, human review plan
Evidence: decision context, human oversight plan, accuracy review
Reviewer Directory
Use this as a quick legend when you need to understand why someone appears in a route.
Business need, role fit, department readiness
Business need, expected benefit, accountable owner
Data classification, minimum necessary use, access scope
Final data-domain authority, exceptions, high-risk data sharing
Data approval appropriate to classification and domain
Security controls, integrations, identity, logging, vendor posture
Integration impact, supportability, system permissions
Purchasing path, contract coordination, vendor requirements
FERPA, privacy, contract risk, records, regulatory obligations
Compliance-sensitive or contract-sensitive requests
Institutional risk acceptance and strategic fit
High-risk, novel, disputed, or cross-functional requests
Agentic systems with sensitive data or high-impact capabilities
Operational accountability, training, monitoring, and reassessment
FERPA and student-record use
Action boundaries, workflow impact, rollback, user guidance