Knowledge base

AI Agent Approval Gates: Which Actions Wait for a Person

Before anything is built, the proposal states which actions an agent may take by itself and which must wait for a person. This is how that boundary is set and checked.

Safety & ownershipUpdated 30 Sep 20262 min read
On this page
  1. Three permission levels
  2. Set in the proposal
  3. The action log
  4. When a script is better

Each action gets one of three permission levels

Every tool the agent can reach carries a label. Automatic actions run straight away, approval actions pause until a person clicks, and forbidden actions never run. An action that is missing from the list counts as forbidden.

LevelUsual examplesWhat happens
AutomaticLookups and order-status answersThe agent acts and writes a log row
Needs approvalRefunds, cancellations, outbound messagesThe agent prepares it and waits for a person to click
ForbiddenAnything not on the listThe agent has no way to call it

The boundary is agreed before the build

The written proposal includes the permission table itself. You choose where the line sits when you accept the work, rather than after something has gone wrong.

One log row for every action

Each action leaves a single row: the role that acted, the tool it used, the time, the outcome and the person who approved it. You can read back anything the agent did and correct it.

The log is kept on your own accounts and written in everyday language, so reading it does not depend on us.

When a script is the safer choice

Some tasks follow fixed rules and need no judgment. Where a plain script would be safer than an agent, the reply says so and the script is what gets built. Agents are kept for decisions that call for judgment inside set limits.

How approvals fit into the wider project is covered in how engagements run.

Start

Not sure what you need? Ask in writing.

Describe the work in a few lines. We will reply in writing within one business day with what we would build and how.