Designing Guardrails: What AI Can Do, What Requires Human Approval
Eli runs talent acquisition operations at a 1,200-person regional hospital network, leading a team of nine recruiters who fill roughly 60 requisitions a month across clinical and administrative roles. When his team adopted an AI assistant, adoption was enthusiastic and completely unstructured. One recruiter used it to draft outreach. Another used it to rank applicants and auto-route the bottom half to a rejection template. A third pasted accommodation requests into the chat to "get a quick read." Three different recruiters, three very different levels of legal exposure, and no document anywhere that said which uses were allowed. Eli did not have an AI problem. He had a guardrails problem. This lesson is the framework he built to fix it: a decision matrix that says, for every recruiting task, exactly what the AI can do on its own, what it can assist with under human approval, and what it must never touch.
Why Guardrails Are a Legal Requirement, Not a Preference
The most important sentence Eli put at the top of his policy was this: the employer is accountable for every hiring decision regardless of the tool that produced it. Under Title VII, the Age Discrimination in Employment Act, and the Americans with Disabilities Act, liability attaches to the organization, not to the software vendor. If an AI tool screens out candidates over 40 at a higher rate, or filters out applicants who use assistive technology, the hospital network answers for it. "The algorithm did it" is not a defense the Equal Employment Opportunity Commission recognizes. The EEOC made this explicit in its guidance on AI and the ADA and in its broader technical assistance on automated systems: existing civil rights law applies in full to algorithmic tools.
This reframes guardrails entirely. They are not productivity etiquette. They are the mechanism by which Eli keeps a documented human decision-maker attached to every consequential outcome, so that when a process is challenged, there is a person who reviewed it, a reason that was recorded, and a record that the tool informed rather than replaced human judgment. A guardrail is the difference between defensible and indefensible.
There is a second reason, and it is the one that convinced Eli's team faster than the legal argument did. AI is useful as a tool and dangerous as a decision-maker, and without an explicit line between the two, the line moves on its own. Call it AI creep. Drafting becomes sending, because the draft was good enough and someone was busy. Summarizing becomes deciding, because nobody opened the source notes. Support becomes replacement, one small convenience at a time, and no single step in that drift ever looks like a decision anyone made. Guardrails stop the drift by naming, in advance and in writing, where the AI's work has to stop.
The Green, Yellow, and Red Decision Matrix
Eli organized every recruiting task into three zones by a single test: how directly does this task shape who gets hired or rejected, and how visible is an error to a human before it causes harm?
Green zone: AI-assisted, human review optional. These are tasks where the AI produces a draft or a summary that a human can easily inspect, and where an error is low-stakes and reversible. Drafting an outreach message, summarizing interview notes, extracting structured fields from a resume into a table, formatting a job description for readability, compiling public research on a company. The output is transparent, the consequence of a mistake is a revision rather than a wrongful rejection, and nothing about who advances is being decided. The AI assists; the human glances and ships.
Two more tasks belong in green, and both are worth stating explicitly because teams tend to either over-restrict or over-trust them. The first is compiling research and background material, pulling together publicly available context on an employer, a specialty, or a market before a call. The second is matching resumes against clear, explicitly stated keyword criteria, which is safe for the same reason a hand-written rule is safe: the criterion is visible, a human can read it, and anyone can check whether a given resume met it or not. Keep one boundary in mind on that second one. Keyword matching stays green while it is organizing and surfacing. The moment a match score starts determining who advances and who is dropped, it has become a decision tool, and it leaves this zone entirely. The unifying logic of green is that the output is transparent, humans can see and verify what the AI did, the cost of an error is moderate, a wrong summary or a draft that needs another pass, and nothing here is decision-making. It is decision support.
Yellow zone: AI-assisted, human approval required before the output affects a candidate. These are tasks where the AI surfaces something that influences a decision but does not make it. Flagging a potential resume gap, identifying possible concerns from screen notes, organizing candidates side by side for comparison, suggesting interview questions tied to a competency. The danger here is silent escalation: a "flag" becomes a reason to reject if no one is required to evaluate it. In the yellow zone, a named human must review the AI's input, decide whether it is legitimate, and own the resulting decision. The handoff is mandatory and documented.
Four recurring tasks live here and are worth spelling out with their handoffs attached. Red flag identification: the AI flags, a human decides whether the flag is legitimate. Concern evaluation: the AI identifies a possible issue, a human evaluates what it means. Candidate comparison: the AI organizes the information side by side, a human decides who is stronger. And assessment of how a candidate would work with the team: the AI may report observations drawn from notes, but a human decides what those observations mean for fit, and never on the basis of who the candidate resembles. Every one of these involves a judgment call, a fairness consideration, or organizational context the model cannot fully hold. The AI is a powerful lens here. It is not the eye.
Red zone: humans only, AI must not decide or act. These are tasks that carry adverse impact, legal accountability, or protected-characteristic judgment. Ranking or scoring candidates in a way that determines who advances, issuing a rejection or an offer, making a final hiring decision, evaluating an accommodation request, or determining anything touching a protected characteristic. The AI may not perform these autonomously, and in several of them it should not participate at all. The cost of an error is a discriminatory outcome and direct legal exposure, and that cost is exactly what the law assigns to the employer.
Three additions complete the red list. Conducting reference calls or candidate interviews is a human activity end to end; a conversation with a candidate or a former manager is not a task to hand to a system, whatever the scheduling pressure. Determining whether something constitutes discrimination or a compliance problem is a legal judgment, and a model that has learned what such findings usually look like is not qualified to make one. And any decision about accommodations or about protected characteristics stays with trained humans, without exception. The common thread across the whole red zone is that these decisions are too consequential, too legally sensitive, or too dependent on human judgment and accountability to be delegated. Accountability in particular cannot be delegated to a system that cannot hold it.
Where the Line Actually Falls: Ranking, Rejection, and Adverse Impact
The cleanest way to draw the green-yellow-red line is to ask whether a task is an automated employment decision tool, because that is the category the law cares about most. Drafting, summarizing, and formatting do not determine outcomes, so they sit in green. The moment an AI ranks, scores, or filters candidates in a way that materially influences whether a person advances, it has become a decision tool, and a decision tool is where adverse impact lives.
Adverse impact is the legal concept that a facially neutral process can still be discriminatory if it produces substantially different outcomes for a protected group. A resume screen that downranks employment gaps will disproportionately affect women who took caregiving leave. A keyword filter trained on a mostly male engineering team can learn proxies for gender. None of this requires intent; under the disparate impact standard, the outcome is what is measured. That is precisely why ranking and rejection belong in the red zone with a human in the loop: a person who can be asked to explain, justify, and correct the outcome.
NYC Local Law 144 and the Bias Audit Requirement
Eli's network hires in New York City, so one law shaped his red zone directly. NYC Local Law 144, in effect since July 2023, regulates what it calls automated employment decision tools, defined as tools that use machine learning or similar techniques to substantially assist or replace discretionary decisions about hiring or promotion. If the hospital uses such a tool, three obligations attach. First, the tool must pass an independent bias audit within the prior year, conducted by an auditor who calculates selection rates and impact ratios across sex and race or ethnicity categories. Second, a summary of the audit results must be published. Third, candidates and employees who live in NYC must be notified at least ten business days before the tool is used, and told what data it assesses.
The practical guardrail Eli derived is sharp. An AI that ranks or scores applicants to substantially assist a hiring decision is an automated employment decision tool, and the network cannot use it without a current bias audit and candidate notice. An AI that drafts an outreach email is not, because it assists no discretionary selection decision. So the green-to-red line in his matrix is not only about good practice; for New York roles it is the difference between a compliant process and an unaudited tool used without notice. Eli's rule: no ranking or scoring tool goes live in a New York requisition until Legal confirms a passing audit and the notice language is in the posting.
ADA Accommodation: The Clearest Red Zone
Accommodation is the case where Eli made the rule absolute: AI must never assess, summarize for a decision, or route an accommodation request. Under the ADA, when a candidate requests a reasonable accommodation, the employer must engage in an interactive process, an individualized, good-faith dialogue about that specific person's needs. That process is the legal opposite of automation. It requires human judgment, confidentiality, and the flexibility to consider options a model would never propose.
There is a second ADA trap that lives upstream in the green and yellow zones. An AI screening or assessment tool can itself screen out qualified people with disabilities, for example by penalizing a resume gap caused by a medical condition, or by using a timed assessment that disadvantages someone using a screen reader. The EEOC has warned employers specifically about this. So Eli's accommodation guardrail has two parts: requests themselves are red zone and handled only by a trained human, and any AI tool that touches screening must be checked for whether it could disadvantage candidates who need accommodations, with an obvious, advertised path for a candidate to request an alternative.
A Worked Example: Routing a Batch of Applicants
Consider a single morning on Eli's team. A nursing requisition closes with 240 applicants. Without guardrails, the temptation is to ask the AI to score all 240 and auto-reject the bottom 160. With the matrix, the work splits across zones. The AI extracts structured fields, license type, years of experience, certifications, from all 240 resumes into a table. That is green: pure formatting and extraction, reviewed at a glance. The AI then highlights which applicants appear to be missing the required state license, surfacing perhaps 35 of them. That is yellow: a recruiter must confirm each flag, because a license may be present under a former name or pending transfer, and a wrong auto-reject is a wrongful rejection.
Here is the number that matters. Suppose the recruiter reviews those 35 flags and finds that 6 were false positives, candidates who were in fact licensed. That is a 17 percent error rate on the flag, and every one of those 6 would have been wrongly rejected by an autonomous system. If even one belonged to a protected group, that auto-rejection is an adverse-impact event the network would have to answer for. The final ranking of the remaining qualified candidates and every rejection notice stay in the red zone: a human recruiter decides the slate, and a human approves each rejection. The AI handled the volume; the human owned the decisions. That division is the entire point of the matrix.
Building Your Own Framework in Five Steps
Eli did not arrive at the matrix by inspiration. He built it in five steps, and any team can repeat them in an afternoon.
- Inventory the workflow. Write down every task on which anyone on the team currently uses AI, including the informal uses nobody has admitted to yet. You cannot draw guardrails around work you have not listed, and the unlisted uses are usually the risky ones.
- Categorize by zone. For each task ask three questions in order. Can the AI do this on its own? Does this require human judgment before it affects a candidate? Should the AI not be doing this at all? The answer places the task in green, yellow, or red.
- Define the handoff points. For every task, say precisely where the AI's work stops and a human takes over, in plain language. Eli's model handoff reads: the AI summarizes the interview notes, the summary goes to the hiring manager, and the hiring manager reviews it and decides whether the candidate moves forward. Written like that, nobody has to guess.
- Set approval requirements. For every yellow task, name who approves and what standard they apply. One of Eli's earliest standards was that when the AI raises a concern about how a candidate would work with the team, two team members who have each read the assessment must separately agree the concern is legitimate before it can affect the decision. Two independent reads make it much harder for a stray model judgment to become a rejection.
- Document and communicate. Write the guardrails down, distribute them, and train on them. An unwritten guardrail is a preference, and preferences drift. A written one is a policy you can point to, audit against, and hold people to consistently.
The Zones Applied Across the Funnel
Abstract zones become useful when you map them onto the actual stages of your process. Here is how Eli's matrix reads stage by stage, and it is a reasonable starting template for most teams.
Sourcing and outreach. Green covers research compilation and drafting the message itself. Yellow covers filtering for candidate quality and deciding which prospects to prioritize, since both influence who ever hears from you. Red covers final approval of the outreach before it goes out, which stays with a person: the AI writes, the human sends.
Screening. Green covers resume summarization and skill extraction. Yellow covers identifying red flags and possible concerns. Red covers the screening decision itself. A human decides who advances, every time.
Interviewing. Green covers scheduling coordination and note-taking support. Yellow covers assessment of the interview and evaluation of demonstrated skills, where the AI can organize evidence but a human weighs it. Red covers the interview outcome decision, which belongs to the interviewers and the hiring manager.
Offer and close. Green covers offer documentation and tracking acceptances. Yellow covers compensation analysis and any counter-offer recommendation, which a human reviews before it reaches the candidate. Red covers the final offer decision and contract approval, which carry both financial and legal consequence and stay firmly with people.
Read down the red column and a pattern appears. Every stage ends with a human decision. The AI does more work at the front of each stage than most teams expect, and none at the end of any of them.
Three Anti-Patterns
- No guardrails at all. Using AI without any framework for what it may and may not do is where Eli started, and the failure is AI creep: what began as support quietly becomes replacement, because nobody ever decided it should not. The fix is to set explicit guardrails before adoption rather than after an incident.
- Guardrails that are too restrictive. The opposite failure is real and more common than people admit. Keeping every task in the green zone, or forbidding AI from any work that touches a candidate, means you are not using it for decision support in the places where it would genuinely help, and your recruiters go back to doing by hand what a tool could organize in seconds. The fix is honesty about where human judgment is actually required, and willingness to use AI freely everywhere else.
- Unclear handoff points. The AI does its work, but nobody can say exactly where human approval happens. This fails quietly: work gets pushed forward without proper review, and the review that was supposed to occur turns out to have been everyone's assumption and nobody's job. The fix is to define the handoff point explicitly for every task, in writing, by name.
Operationalizing the Matrix: Handoffs and Documentation
A matrix only works if the handoff between zones is explicit and recorded. For each yellow and red task, Eli defined three things: what the AI produces, who the named human approver is, and what the approval standard is. For an AI-flagged concern from screen notes, the standard is that the recruiter and the hiring manager must independently agree the concern is job-related and consistent with business necessity before it can affect the decision. For a New York ranking tool, the standard is documented confirmation of a current bias audit and candidate notice before activation. For any rejection, the standard is a human-reviewed, job-related reason recorded in the applicant tracking system.
The documentation is not bureaucracy; it is the evidentiary record that makes the process defensible. If the EEOC or a candidate's attorney later asks who decided and why, Eli can produce a named human, a recorded reason, and proof that the AI informed rather than determined the outcome. He distributes the matrix as a one-page policy, trains every recruiter on it, and tests it with a simple drill: he describes a scenario, "the AI flagged this candidate as a culture concern, what happens next," and if two recruiters answer differently, the guardrail is not yet clear enough.
The Vocabulary, in One Place
- Guardrails. The lines you draw specifying which decisions AI can support on its own and which require human approval.
- The green zone. Tasks the AI can handle autonomously: low consequence, transparent output, easy to verify.
- The yellow zone. Tasks where the AI provides input but a named human makes the decision.
- The red zone. Tasks the AI should not do: too consequential, too legally sensitive, too dependent on human accountability.
- The handoff point. The specific moment where the AI's work stops and human judgment begins. If you cannot name it, it does not exist.
Practice
- Inventory your own workflow. List every task for which you personally use AI in recruiting. Assign each one to green, yellow, or red, and note any you are unsure about, because the uncertain ones are where your policy needs to be sharpest.
- Define your yellow-zone guardrails. For each yellow task on your list, write three things: what the AI produces, who approves it, and what standard that approver applies.
- Map your handoff points. For your two or three most critical processes, diagram the sequence: the AI does this, then a human reviews, then the decision is made. Look at the diagram and ask whether the handoff is genuinely clear or merely implied.
- Test the guardrails on your team. Describe a scenario out loud to your colleagues: "the AI flagged this candidate as a concern about team fit, what happens next?" If you get different answers from different people, your guardrails are not clear yet, and you have just found the gap for free.
- Document the framework. Write your guardrails up as a single page, share it with the team, and make it canonical. An agreement that lives only in a conversation is not a guardrail.
Reflection
- Which recruiting decisions are you currently making without a human approval step that should have one?
- If your guardrails were clearer, what would actually change about how your team uses AI day to day, in both directions, more use and less?
- What is your biggest concern about AI in recruiting right now? Look at it honestly: is it a guardrails issue, and if so, which zone does it belong in?
- How would you explain to executive leadership why certain decisions require human approval, in terms of accountability and legal exposure rather than caution?
Putting It to Work This Week
Clear guardrails are what let you use AI confidently instead of nervously. When everyone on the team knows what the AI may and may not do, the tool stops being a source of quiet risk and becomes something you can scale deliberately, because AI creep has nowhere to creep into.
So build the first slice this week. Take one stage, sourcing and outreach is the easiest place to start because the stakes are lowest, and define its green, yellow, and red zones. Write down the handoff points. Share the page with your team and ask them to poke holes in it. Then repeat for screening, and keep going until the whole funnel is covered.
Related Lessons
- Human Touchpoints: Strategic Moments for Human Review goes deeper on where in a process a human review step buys the most protection per minute spent, which is exactly the question the yellow zone raises.
- Decision Rules: Explicit Criteria for Escalation extends the approval standards in step four into explicit, written criteria that decide when something must move up rather than sideways.
- Escalation Paths: When to Involve Legal, Compliance, DEI, or Leadership covers what happens when a red-zone question lands on your desk and needs to leave it.
- Responsibility and Accountability in AI-Assisted Decisions develops the accountability argument underneath this entire lesson: why the employer answers for the outcome regardless of which tool produced it.
- Documenting Decisions: Clear Records for Legal and Fairness Review turns the documentation habit described here into a record that holds up under scrutiny.
- Team Agreements: Building a Culture of Responsible AI Use is the cultural counterpart to the written matrix, covering how a team actually adopts and sustains boundaries at scale.
Key Takeaways
- The employer is accountable regardless of the tool. Title VII, the ADEA, and the ADA assign liability to the organization, not the AI vendor. "The algorithm did it" is not a defense the EEOC recognizes, which is why every consequential decision needs a documented human owner.
- Sort every task into green, yellow, or red. Green is AI-assisted drafting, summarizing, and formatting where errors are visible and reversible. Yellow is AI input that requires human approval before it affects a candidate. Red is ranking, rejection, offers, and protected-characteristic judgment, which stay with humans.
- The line is drawn at ranking and rejection. The moment AI scores or filters candidates in a way that influences who advances, it becomes a decision tool that carries adverse impact, and adverse impact is measured by outcome, not intent.
- NYC Local Law 144 makes the line a compliance boundary. An automated employment decision tool that substantially assists hiring or promotion requires a current independent bias audit, a published results summary, and candidate notice at least ten business days in advance. A drafting tool does not; a ranking tool does.
- Accommodation is an absolute red zone. The ADA interactive process is an individualized human dialogue that AI must never assess or route, and any screening tool must be checked for whether it disadvantages candidates who need accommodations, with an advertised path to request an alternative.
- Yellow-zone flags need a mandatory human check. A worked review of 35 license flags surfacing 6 false positives, a 17 percent error rate, shows why an autonomous auto-reject is a wrongful-rejection risk while a confirmed human handoff is not.
- Document the handoff or the guardrail does not exist. For each yellow and red task, name what the AI produces, who approves, and the approval standard, and record the human reason in the applicant tracking system so the process is defensible when challenged.
Skill.re