Skip to main content
DoneThat

AI Adoption GuideGovernmentAuthorize

Multi-agency sign-off orchestrator

Agentic AI tracks authorization steps across departments, routes to the next approver automatically, and escalates on SLA breach.

Government processPlanFundAuthorizeDeliverInspectEnforceReportClose

By Don, DoneThat’s AI coach · updated

What a routing action is allowed to contain

The usable output is a routing action that cites the RACI step it is executing and the SLA clock that step runs against. It is not a permit, a concurrence, or a signed authorization. If the next approver is not named on the loaded map, the next-approver field stays empty. The model does not invent an agency, a desk, or a likely office to keep the file moving. A human still signs.

A case coordinator should reject any hop that cannot point to both citations. Permitting and casework platforms (Accela, Salesforce Government Cloud, ServiceNow, Microsoft) can hold the task, the timer, and the audit fields.

The action should carry the RACI step identifier and label, the named role or person only if the map supplies one, the SLA clock as recorded in the workflow, and the reason the hop is due now. It should not carry a guessed agency name, a backfilled clock, or language that treats the route itself as approval.

Load the sign-off map before the first hop

Do not route from memory, from a similar file, or from a list of agencies that usually see this type of application. Load the sign-off map that belongs to this application type, this location, and this version of the ordinance set. The map is the RACI for this file: which step exists, who is named, which clock is attached, and which steps are optional or not yet staffed.

Confirm three things before the first hop:

  1. Completeness of the packet the next named reviewer is entitled to see. Re-check the application completeness checker so you are not starting clocks on an incomplete submittal.
  2. The map version. If a regulatory change alert has fired since the map was last confirmed, stop and have the human owner confirm whether a new concurrence appeared, a clock changed, or a named office was withdrawn.
  3. Named versus unstaffed rows. A row that lists a function with no person or office of record is not a routing target. Empty stays empty.

If the map is missing, stale, or internally inconsistent (two Accountable parties for the same signature, or a clock with no owner), the orchestrator produces no hop. The coordinator opens a map-repair task. Guessing the next office is the failure mode that creates ghost reviews and later claims that the department was notified.

Route only named steps and leave blanks empty

For each remaining step on the map, ask one question: is the approver named? Named means a role or person the workflow can address without invention, such as a recorded Fire Marshal queue, a named Public Works reviewer, or a Building Official of record. If yes, emit a routing action that cites that RACI step and that step's SLA clock. If no, leave the next-approver field empty and surface the blank to the coordinator. Do not substitute Environmental Health, the state, or whoever handles grease traps, because those strings are not on the map.

A commercial kitchen build-out lists building, fire, public works, and environmental health concurrences on the local map. Building Official, Fire Marshal, and Public Works are named, with recorded clocks on each of those steps. Environmental Health appears as a required Consulted step, but the named-approver field is blank because the seat is vacant and no acting official has been entered. The orchestrator routes to Building, Fire, and Public Works. It does not create a task for the health department, pick a neighboring jurisdiction, or reuse a county inbox from a different file. The blank stays empty until a human names an official of record. Only then does a hop exist.

Routing to an unnamed office is the first failure mode. It looks like progress in the queue and it is not a lawful handoff. The file shows activity and still has no accountable recipient.

When a named step also needs conditions rather than a naked yes or no, keep that work on the named reviewer. The condition generator for approvals can draft proposed conditions for the human who holds the signature. It does not travel with a hop into a blank office.

Escalate on the recorded SLA clock, never a guessed one

Escalation is allowed only against a clock that already exists on the loaded map or in the workflow record for that named step. The action should cite the clock as recorded: identifier, start rule, duration, and who receives the breach. If no clock is recorded, there is no SLA breach to declare. Do not invent a five-day fire review because another city uses one. Do not copy a building clock onto an environmental health row that has no timer. Do not start a clock because the applicant is calling.

Inventing an SLA is the second failure mode. A made-up clock creates false breach notices, false pressure on the wrong desk, and an audit story that cannot be defended. If the map has no clock, the coordinator either obtains a recorded clock from the process owner or leaves the step without an automated escalation path.

When a recorded clock is approaching breach, the orchestrator may notify the named step owner and, if the map names an escalation recipient, route a reminder or an escalation task to that named person. If the escalation recipient is not named, the escalation target stays empty. The coordinator is told the clock will lapse without a named recipient. Breach handling does not approve the step and does not skip the human. It only makes the delay visible to people the map already named.

A routed task is not a signature

The third failure mode is treating a routed task as signed. A task in a Fire Marshal queue means the step was offered to a named recipient. It does not mean fire has concurred. Status language must stay precise: routed, viewed, in review, returned with comments, approved by named official, denied by named official. Routed never collapses into approved.

The human still signs. The orchestrator may assemble the packet, name the RACI step, display the remaining clock, and place the record in the correct queue. The signature, concurrence, or rejection is a human act in the system of record. Do not auto-advance the file to issued, recorded, or closed because every named hop left the queue.

When the named official does sign, capture the act in the same file the hops came from. The audit trail auto-documenter should record who was routed, which RACI step and clock were cited, which fields were left empty and why, who signed, and which blanks remained at signature time. Empty fields later filled by a human naming an acting official should show as a map update, not as an original hop.

If a later reviewer asks why environmental health never received the kitchen file, the answer should be readable without folklore. The map required the step, the named approver was blank, no agency was invented, and the coordinator parked the file until an official of record was entered. The route is only as good as the names and clocks it is willing to leave blank.

Is this worth automating for you?

Whether this pays back depends on how much time it takes your team today. Most teams estimate that from memory, and the estimate is usually wrong in one direction or the other. This one is rated high effort to implement, so the baseline matters more than usual.

DoneThat reconstructs where the time actually went, with no timers to forget, so you can measure the baseline before committing to a project and check the gain afterward.

Measure the baseline first