Skip to main content

Human Approval

Human approval is a control for actions with meaningful impact. It should be based on action sensitivity, not applied indiscriminately to every AI interaction.

Default Approval Matrix

ActionDefaultReviewer should verify
Search or read permitted dataAutomaticAccess scope and source
Create an internal draftAutomatic or confirmationSensitive content and intended audience
Create an internal ticket or taskConfirmation for broad agentsProject, owner, priority, duplicates
Send or publish externallyConfirmationRecipient, content, attachments, classification
Update a business recordConfirmationTarget ID, changed fields, downstream effects
Export dataConfirmationPurpose, destination, minimum necessary data
Change permissions, budgets, production, or legal stateConfirmation plus provider-side authorizationIdentity, scope, rollback, owner approval
Delete or perform an irreversible actionDisabled or exceptional approvalNecessity, backup, exact target, recovery path

Effective Approval Requests

An approver needs enough context to make a real decision. Show:

  • the action and target system,
  • the exact recipient, record, environment, or resource,
  • the arguments that matter,
  • a concise reason for the action,
  • the expected effect and whether it is reversible,
  • which agent, conversation, workflow, and connection requested it.

Do not hide a batch of materially different changes behind one generic confirmation.

Review and Tuning

If approvals become noisy, separate read, draft, and write functions or narrow the workflow. Do not remove confirmation from high-impact actions only to reduce friction. Review approvals and outcomes in Tool Executions.