Human approval for AI agents
Agents do the work. A person decides what leaves.
Mark any tool as needing approval. The run pauses before the call, the reviewer sees exactly what will be sent, and nothing happens until someone says yes.
The problem
An agent that can send email can also send the wrong one.
The useful agents are the ones that act: they reply to customers, post for the company, update records. Most teams end up choosing between not letting them act at all and hoping they get it right. Approvals are the third option: the agent does the work, and a person signs off on the few steps that are hard to take back.
- It reaches a person. Sending an email, posting to LinkedIn or X, replying to a customer.
- It moves money. Refunds, payments, purchases, changes to a plan.
- It changes records or access. CRM updates, database writes, inviting users, creating keys.
How it works
The run stops at the exact moment it wants to act.
Reading, searching and thinking stay automatic. Only the calls you mark wait for a person.
- Mark the tool. On an agent's Tools tab, switch a tool from Auto-run to Approval required. Nothing else about the agent changes.
- The run pauses before the call. The tool has not run yet. The agent's owner gets a notification in AgentOS.
- The reviewer sees the real call. An email shows as its recipient will read it: to, from, subject and body. Not a summary written by the agent.
- Approve runs it as shown. Reject tells the agent. A rejected call never runs; the agent is told, skips that item and carries on. A note left with the decision becomes the agent's reason.
One decision per run
Three emails, one decision.
When a run wants several gated calls at once, they arrive as one card: the first in full, then approve all, review them one by one, or reject all. The run carries on once every call is decided.
The queue shows what is waiting, for which agent, and how long is left. Each request expires after 24 hours, and the ones close to their deadline are flagged. A My agents tab narrows the queue to the agents you own.
Coverage
Know which agents can act without asking.
The Coverage view shows how many agents and tools need approval, and the risk gaps: tools that reach an outside service, write files or start other agents, and still run unattended. Close a gap from the same screen.
The History view shows how the process is holding up: how fast people decide, how many requests were decided before they expired, and which tools get rejected most.
What you get
Every decision on the record.
- Who decided, and when. Each request keeps the person who decided, the time and their note, and shows on the run it paused.
- Nothing waits forever. A request nobody answers expires after 24 hours. The call never runs, and the run ends as failed with the reason.
- Roles that fit the risk. Owners, admins and members can decide. A request that changes workspace settings needs an owner or admin.
- Questions, not only approvals. An agent can also stop to ask a person a question, with up to eight choices, and carry on with the answer.
- Decisions from code. List and decide approvals with a workspace key through the API, or from Claude, Cursor or any MCP client.
- Changes on the audit log. On Enterprise, every change to which tools an agent may run unattended is written to the workspace audit log.
In our own workspace
We gate what leaves the building.
We run our own company on AgentOS, and our social posts and first outreach emails all wait for approval.
Every scheduled post on our LinkedIn page and every first outreach email waits for a person to approve it. That part works exactly as intended: none of them goes out until someone has read it.
The same post is honest about the cost: an approval nobody answers expires, so we ask for fewer, better decisions rather than removing the gate.
Go deeper
How it works, in detail
More in Control
Decide what agents may do on their own, and keep the rest for a person.
Give one job to an agent this week.
Start with one repetitive workflow, gate the sensitive step behind your approval, and read the first run end to end.