A person should, for every exception that gets approved and not fixed.
The design most teams are about to copy comes from Vercel. Tomasz Tunguz wrote up how COO Jeanne DeWitt Grosser's team moved their inbound sales agent from a 1,000-line prompt to 14 rules in code, with the model kept for judgment. A second agent watches for breaches of the rules and fixes them or blesses the exception. The write-up does not say how blessings are recorded or reviewed, so this is about the pattern and not about Vercel.
An approved rule break is the most informative event in a rules system. It only exists when a rule did not fit. I learned that from a pricing migration at a $40M ARR company, where the plan modeled 50 exceptions a week and we got 600, three reps negotiated unauthorized extensions, and every one of those accounts still counted as migrated. The exceptions were countable only because a person had to approve each one.
So keep the escalation agent, and add three lines. Every blessing is logged with the rule, the case, and the reason. A named person reads all of them every week. A rule that keeps getting blessed is rewritten or becomes a new rule. Sample the routine output. Read every exception.
The full argument is in Fourteen Rules, and Who Blesses the Exception, and the count itself comes from Percent Migrated Is a Vanity Metric.