Put an approval gate in your application between the agent’s proposed tool call and the code that executes it. When an action requires review, show an authorized person the exact tool, arguments, and likely effect; execute only after that person explicitly approves that specific request. A model instruction to “ask first” is not a substitute for controlling the execution path.
What should require human approval?
There is no universal definition of “high impact” in the API references below. Set an application-owned policy based on your product’s authority and the consequences of an action. Possible categories include:
- Sending messages or other external communications.
- Spending or transferring money.
- Deleting or materially changing important data.
- Changing access permissions or security settings.
- Starting an operation that affects the physical world.
These are policy-design examples, not categories or thresholds prescribed by OpenAI’s APIs. Decide which actions need review in your own context, and ensure the policy is enforced by the application rather than left to the agent’s discretion.
Where does the approval gate belong?
Place the gate after the agent proposes a tool call but before the application invokes that tool. The application should inspect the proposed action against its policy. If approval is required, it should hold execution, create a review request for that exact action, and wait for an explicit decision. This is the essential control point: approval-related API objects provide workflow mechanics, but your application must connect them to the code that actually executes tools.
#1 Best Overall
- Receive the proposal. Capture the proposed tool name and arguments without executing the tool.
- Apply your policy. Determine whether that tool call requires approval. Actions that do not require review can follow your normal execution path.
- Create a request for review. Bind it to the precise proposed tool and arguments. Show an authorized reviewer those details along with a plain-language explanation of the likely effect.
- Wait for a decision. Require an explicit approval or rejection tied to that request. Silence, a timeout, or an unrelated confirmation is not approval.
- Enforce the result. Execute only the approved action. On rejection or expiration, do not execute the proposed action; return a safe status to the agent or user.
- Record the outcome. Log the request, action details, reviewer identity, decision, time, and execution result under your organization’s access and retention rules.
If the proposed arguments change after review, treat the changed proposal as a new action and obtain approval again. Otherwise, the reviewer may have approved something different from what the application executes.
Which OpenAI API mechanism fits?
OpenAI documents approval-related control points in several API contexts. They are distinct mechanisms, not interchangeable forms of one protocol. Choose the one that matches the API and tool integration your application uses, and confirm its current behavior in the relevant reference.
| API context | Documented approval workflow | What to account for |
|---|---|---|
| Responses API | The MCP approval request represents a request for human approval of a tool invocation and includes the tool name and arguments, which can inform what your application displays to a reviewer. OpenAI Responses API streaming reference. | The reference documents the request information; your application still needs to connect review decisions to tool execution. |
| Realtime API | The approval response is associated with an approval request ID and includes an approve boolean and an optional reason. OpenAI Realtime API server events reference. |
Use the request association to apply the decision to the right pending action. The optional reason can preserve an explanation for the decision. |
| Assistants API | A function call can put a run in requires_action. The application must run the functions and submit their outputs before the run proceeds; the run expires if the required outputs are not submitted before its expiry time. OpenAI Assistants API run lifecycle guide. |
Account for the run’s expiry while handling approval. This is API-specific lifecycle behavior, not a general approval protocol. |
How should the approval decision fail safely?
Define the pending-request behavior before deploying the feature. The approval mechanism is only effective if the application does not fall through to tool execution when review is unresolved or fails.
- Approved: Execute the exact action that was reviewed, then record its result.
- Rejected: Do not execute it. Return a safe status to the agent or user; where appropriate, include the reviewer’s reason.
- Expired or timed out: Do not treat the missing response as approval. Close or expire the request and leave the action unexecuted.
- Arguments changed: Do not reuse the earlier decision. Create a new request for the modified action.
- Duplicate or conflicting requests: Ensure a decision can authorize only its intended pending request, rather than a different or repeated action.
- Execution error: Record that approval was granted but execution failed; do not report success merely because the reviewer approved.
The documented Assistants API lifecycle specifies expiration if required outputs are not submitted in time. The exact timeout, retry, and cancellation behavior for other integrations depends on your application and the relevant API’s current specification.
Recommended Free Tools
Rank #3
What should you test?
Test the full path from proposal to tool execution, not just the review screen. In particular, verify that the tool cannot run until the correct decision is received.
- Approval of a request executes only the reviewed tool call and arguments.
- Rejection, timeout, and expiration leave the action unexecuted.
- A changed argument requires a fresh approval.
- A duplicate decision or stale request cannot authorize a different action.
- Reviewer identity, decision, timing, and execution outcome appear in the audit trail as intended.
- Errors in the approval service or execution path do not accidentally bypass the gate.
These checks are engineering recommendations; the API references describe workflow mechanics but do not claim to implement every safeguard automatically.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

