# Approval & recovery
Product Agents · Field sheet 02 · v1, September 2026

Review one real operation, including the bulk case. Show the actual proposed change beside this worksheet.

## Operation
- User intent:
- Requested action, objects, and audience:
- Preview of the before/after values:
- Included, excluded, and failed-to-load records:
- What the system cannot know yet:

## The decision card
- Does the action label name the outcome?
- Can the user inspect exactly what will change?
- Does a bulk operation show scope, exceptions, and partial-success behavior?
- Are costs, external visibility, and irreversible steps disclosed where they matter?
- Can the user revise the selection without starting over?
- Does the user have permission for every included object?
- Is the approval bound to this exact action, scope, and object version?
- When does approval expire or need to be requested again?

## After the click
- Durable operation identifier:
- How execution is deduplicated:
- What the user sees while execution continues:
- What cancel stops, and what it cannot stop:
- Receipt: completed / failed / skipped counts and object-level details:

## Recovery
For each side effect, fill in this table. A compensating action is not necessarily an undo.

| Side effect | Can it be undone? | Time window | What remains after recovery? | Who can recover it? |
| --- | --- | --- | --- | --- |
| | | | | |

## Try to break the promise
- Change one selected record after approval but before execution.
- Revoke a permission before execution.
- Disconnect after some records complete.
- Submit the same approval twice.
- Cancel while one operation is in flight.
- Attempt recovery after another person changes the record.

Record the observed behavior, the promise the UI makes, and any mismatch.

Decision:
Owner:
Follow-up:

You may copy and adapt this worksheet for your own team's work.
