AI for HumanIT
All posts
01 Oct 2026 · 4 min read

Claude for Government: two-person approval and the admin basics

Claude for Government is now generally available. Two-person approval for sensitive admin actions is the standout. Here is what that asks of an organisation, plus the budget, SSO and MDM changes.

GovernanceAgentsEnterprise ITAnthropic
Two identical men in black t-shirts simultaneously pressing a glowing green button on a metallic pedestal, looking at each other with puzzled expressions on a dark purple AI for HumanIT branded background.

The detail that jumped out

Two-person approval for sensitive admin actions. That's the line that stopped me when I read the Claude for Government general availability announcement.

The idea itself isn't new. Finance has run on the four-eyes principle for a long time, and the two-person rule is standard practice wherever a single mistake or a single bad actor could do serious damage. What caught my attention is seeing it presented as a headline admin feature for an AI platform.

It's the right instinct. But it's also a very high bar.

Why one approver is already hard

Honestly, most organisations struggle to get a single human reliably in the loop on sensitive operations, let alone two.

You'll know the pattern if you've ever owned an approval step:

  • The request lands in an inbox and sits there.
  • The approver is on leave, in back-to-back meetings or has moved roles.
  • Someone works out that approving without reading is the fastest way to clear the queue.
  • After enough friction, a standing exception gets granted and the control quietly stops being a control.

Add a second approver and you don't just double the safety. You also double the number of people who have to be available, paying attention and willing to say no. That's a lot of cats to herd.

So if agencies can make dual approval work in practice, not just on paper, that's genuinely impressive. The questions I'd want answered before trusting it are the operational ones rather than the technical ones:

  • What counts as sensitive? Draw the line too wide and people drown in requests. Too narrow and the control misses the actions that matter.
  • Who are the two people? If it's always the same pair, you've built a bottleneck. If it's anyone in a large group, you risk both people assuming the other one checked.
  • What happens when nobody's around? Every approval process needs an answer for out-of-hours and holidays that doesn't amount to "skip it".
  • Is the second approval real? The value comes from an independent second look. A colleague clicking yes because the first person already did isn't that.

None of this is a criticism of the feature. Having the mechanism built into the platform is the hard technical part done. The harder part is the human process that sits around it, and that's on the organisation, not the vendor.

The rest of the admin changes

The other changes in the announcement make a lot more sense to me operationally, because they map onto problems IT and finance teams already deal with every day.

Department-level budgets

Budgets set at department level, with spend allocated down to sub-agencies, is just sensible governance. Large public bodies are rarely one organisation in practice. They're a parent with a set of children, each with its own priorities and its own accountability for what it spends.

Being able to set the envelope at the top and divide it below means the people closest to the work can manage their own usage, while the department still has a single view of the total. It's how money already flows in those structures, so the tool fits the organisation rather than the other way round.

SSO through the agency's own identity provider

Single sign-on through the agency's own identity provider, rather than yet another bolt-on login, is exactly what IT teams want to hear.

It sounds dull, and it is, which is the point. Using the existing identity provider means joiners, movers and leavers are handled in one place. When someone leaves, their access goes with everything else, instead of lingering in a separate system nobody remembers to check. For any tool that can touch sensitive information, that's table stakes.

Agents as just another managed app

The part I find most striking is how fast this is normalising. Claude Code and Claude for Microsoft 365 can now be deployed through standard mobile device management, sitting alongside every other app IT already manages.

That's a quiet but significant shift. Not long ago, AI tools tended to arrive through the side door: individuals signing up, browser tabs, personal accounts. Now they're going through the same front door as the rest of the estate.

Agents are quietly becoming just another thing to package, assign and patch.

I think that's broadly good news. It means AI tools inherit the controls organisations already have, rather than needing a parallel set of rules. But it also means they inherit the same responsibilities. Someone has to own the package, decide who gets it, plan how updates roll out and keep track of what version is running where. The novelty wears off fast and the operational work stays.

Over to you

The budgets, the SSO and the MDM deployment all feel like the kind of plumbing that makes adoption possible in a large organisation. Two-person approval is the one that asks the most of the people involved.

So I'll put the question out there: has anyone actually got two-person approval working for real on sensitive operations, AI or otherwise? Not a policy document, but a process people follow on a Friday afternoon when the second approver is on holiday. I'd genuinely like to hear how you did it.

Agents are quietly becoming just another thing to package, assign and patch.
Bruce Cullen
Keep reading

More from the blog