Know Who Is Allowed To Say Yes
A lot of small business workflows break in a place that looks too ordinary to call a systems problem: nobody is sure who is allowed to approve the next step.
That can happen on the shop floor, in the inbox, or in a text thread. A machine needs a repair. Production wants to keep moving. Sales thinks the customer owns the asset. Accounting has no approval to issue a purchase order. The customer contact is out of office. Everyone is trying to protect the business, but the work stalls because authority is scattered across memory, spreadsheets, relationships, and habit.
Or take a simpler customer follow-up problem. A trial customer visits a boutique gym. The coach marks attendance in one app. The owner adds the lead to a spreadsheet. An automated email goes out. A staff member sends a manual text with a different offer. The problem is not that the team lacks effort. The problem is that nobody can see who owns the follow-up, which offer is valid, and when automation should stand down.
This is where many AI projects get pointed at the wrong target.
The tempting question is, "Can AI handle this task?" Can it draft the repair approval? Can it follow up with the lead? Can it summarize the thread? Those are useful capabilities, but they are not the first safety question. The first question is whether the business has a clear enough authority boundary for the system to participate.
Who is allowed to approve the mold repair? Who can charge the customer? Who can offer the gym discount? Who can suppress the nurture campaign? Who should review the exception before it reaches the customer?
If those answers live only in people's heads, automation will either do too little or too much. It will produce drafts nobody trusts, route tasks to the wrong person, or confidently continue a workflow that needed a human stop.
The practical starting point is not a giant permissions project. It is a small authority map around one workflow.
Pick one messy process where approval already causes delay or rework. Write down the handful of states that matter: waiting on owner, waiting on customer, approved to proceed, approved to bill, needs manager review, do not contact, duplicate follow-up suppressed. Then define who can move the work from one state to another.
That gives AI a safer role. It can collect evidence, identify the likely owner, draft the approval request, flag missing proof, and prepare the next action. But the system should also know when it is not allowed to act. A repair can be urgent and still need customer approval. A lead can be warm and still need one owner. A message can look routine and still change who has authority.
This is also how trust gets built with the team. Employees are less likely to fight automation when they can see the boundary. The system is not pretending to be the manager. It is making the current approval mess visible, then asking the right human to decide.
The useful reframe is this: before you ask AI to do the work, ask whether your business knows who can authorize the work.
That answer does not have to be perfect on day one. It just has to be explicit enough that the next action is reviewable.