Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

In ClauseWatch, an AI agent can gather and attach evidence for a compliance review, but it cannot sign the final decision. The move it is not allowed to make is the transition from review to decided: a person must supply a name and rationale, and the signature is recorded with that transition.

What the agent can do—and what it cannot

ClauseWatch is a project by Oleg Vdovin, presented as a tool for people handling compliance files at small companies, including founders and engineers who may not have a legal department. Its central distinction is between preparing a decision and taking responsibility for it. The agent can gather and organize material; only a person can make and sign the final decision.

Vdovin describes the workflow as five states: raised, gathering, review, decided, and dismissed. Of its five transitions, two are available to an agent and three are reserved for a human. The decisive boundary is review → decided, which ClauseWatch treats as the signing step. Read Vdovin’s project post on DEV Community.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How ClauseWatch represents the boundary

Rather than relying only on an instruction telling the agent not to decide, Vdovin says ClauseWatch stores workflow rules as content in a Sanity dataset. The same gate function determines which moves are permitted for both agent and human actions. In the described design, the agent cannot take the signing transition, while the human signing desk provides the route for a person to enter a decision.

Vdovin says the person supplies a name and rationale, and that the signature and transition record are written together. He summarizes the intent this way: “Only a person signs. The agent can prepare every part of this and still not make the move.” This is the author’s account of the implementation and its purpose, not an independent audit of the code or a test of the deployed application.

Why the signing step matters

A compliance workflow may need to collect evidence, surface requirements, and identify possible conflicts without letting the system’s ability to produce a recommendation silently become authority to approve it. ClauseWatch makes that distinction visible in the workflow: the agent prepares the case, then a person takes the final action and leaves a recorded rationale.

Rank #2
Sale
Modern Robotics: Mechanics, Planning, and Control
  • Book - modern robotics: mechanics, planning, and control
  • Language: english
  • Binding: hardcover

That boundary is a design choice, not a complete security guarantee. A workflow rule by itself does not establish who is authorized to sign, whether the agent has other credentials that could bypass the intended path, how rejected transitions are handled, or whether the record is protected and retained appropriately. Those controls need to be considered alongside the workflow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The compliance example is a prompt, not a legal conclusion

Vdovin motivates the project with a question about logs from a high-risk AI system. His post says the EU AI Act calls for at least six months of retention while GDPR storage limitation says personal data should not be kept longer than necessary. The example raises a genuine issue for a compliance review, but the post alone does not establish that the obligations conflict or determine the right retention period for a particular system.

GDPR Article 5(1)(e) says personal data should be kept in identifiable form “for no longer than is necessary for the purposes for which the personal data are processed.” It also provides for longer storage in specified circumstances, including archiving in the public interest, scientific or historical research, and statistical purposes under Article 89(1), subject to safeguards. See the official GDPR text on EUR-Lex.

The applicable AI Act logging obligation, its scope, and how it applies alongside GDPR depend on the relevant provisions and facts. The project post is not a basis for setting a retention period or reaching a legal conclusion; a specific system’s obligations should be reviewed by qualified counsel or responsible compliance professionals.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the project does—and does not—claim

Vdovin describes ClauseWatch as a working core, not a complete compliance product, and says it is not legal advice. The dataset he reports contains two instruments, nine provisions, two requirements, three conflicts, two system profiles, and one workflow. These are counts of this project’s configuration, not measures of compliance effectiveness.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The post describes a public Studio, dataset, server-rendered viewer, and code repository, and says the deployed signing app requires a Sanity login. Those details explain the project’s implementation; they should not be mistaken for independent evidence that its authorization, security, or legal analysis has been validated.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.