Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Put a mandatory approval gate immediately before an AI agent’s consequential action—such as sending a message, changing a record, deleting data, making a purchase, granting access, or publishing content. The workflow should pause, show a reviewer exactly what will happen, record an authorized decision, and then resume the same run or stop. A prompt telling an agent to “ask first” is not an enforcement boundary: the runtime must prevent the action until approval is recorded.

Decide which actions need human approval

Start with the action, not a general rule that the agent should ask before doing anything important. Approval is most effective at the tool or workflow boundary where a side effect is about to occur. A broad agent-level check may not cover every tool call. OpenAI’s guidance describes reviewing a proposed target, action, arguments, calling identity, and scope in authorized cybersecurity workflows; those are useful elements to inspect for other consequential operations too. See OpenAI’s guardrails and human review guidance.

Inventory and classify tool actions

List each action the agent can invoke, the system or data it can affect, and the business owner. Separate read-only retrieval from writes, sends, deletions, purchases, external sharing, access changes, and other actions that alter a system of record or reach someone outside the organization. For each action, note its purpose, affected party, permissions, reversibility, potential consequence of error, and whether it is customer-facing.

Use those characteristics to set review levels. A practical pattern in Microsoft’s human-review runbook is to notify after low-consequence, reversible actions; confirm actions with moderate consequences and a clear right answer; have a person commit drafts that carry the organization’s voice or numbers; and require a named, qualified reviewer for clinical, legal, financial, or safety-related outputs. This is a useful design pattern, not a universal standard. Microsoft’s human-in-the-loop runbook provides the framing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Give low-risk, reversible work only the narrow permissions it needs, with monitoring. Require explicit approval for high-impact, ambiguous, customer-facing, sensitive, or hard-to-reverse actions. Treat financial, legal, personnel, safety, and compliance decisions with particular care.

Write an approval policy before building the gate

Make the policy specific enough that the runtime, reviewer, and workflow owner can apply it consistently. Define:

  • What requires review: action classes, thresholds for amounts or destinations, data sensitivity, and any risk conditions.
  • Who may approve: the authorized role, any required qualifications, and when a second reviewer or escalation is needed.
  • What the decision authorizes: the exact operation, target, and scope. Approval of one proposed action should not silently authorize a different or expanded action.
  • Available decisions: approve, reject, request changes, or escalate, with clear meanings for each option.
  • Failure behavior: what happens on timeout, missing information, conflicting policy, or approval-service failure. For consequential actions, keep execution paused or stop it; never interpret an error or absent decision as approval.
  • Retry controls: how the system prevents the agent from attempting a rejected action through another tool or a rephrased request.
  • Audit fields: the proposal, applicable policy and version, reviewer identity, decision, timestamp, requested changes, execution result, and any exception.

There is no universal timeout or escalation interval prescribed in the cited guidance. Set those values to fit the workflow’s service needs and risk, and leave the action paused if the designated approver has not responded.

Enforce approval in the runtime

The gate must affect execution, not just display a warning or ask the model to comply. When a protected tool is called, the system should return a pending review instead of invoking the tool. Preserve the run state if a decision is delayed. After approval, resume the same run; after rejection, terminate it or route it to a defined alternative. OpenAI’s documentation describes approval interruptions and resuming runs, while noting that input and output guardrails do not run around every custom tool call. Put validation next to the side-effecting tool that needs it. Review the OpenAI Agents SDK human-in-the-loop documentation and API guidance for current, version-sensitive implementation details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The SDK documentation describes approval interruptions across the top-level agent, handoffs, and nested agents. Your application still needs to provide an approval surface, persist the decision and relevant run state appropriately, and ensure the tool cannot execute before the decision is authorized.

For a Microsoft Copilot Studio agent flow

Microsoft documents a preview feature called “Run a multistage approval.” Add it through the Human review connector between flow nodes, then configure manual stages, assignees, approval details, typed inputs, and conditional routes. The action sends requests to assignees and waits for completion before the flow continues. Assigned users can respond through the Teams approvals app, Outlook, or the Power Automate portal.

Microsoft labels this feature preview and subject to change. Its documentation also says AI stages need Copilot Studio Copilot Credits assigned to the environment. Check current availability, licensing, and tenant configuration before making the feature a production dependency. For financial transactions, legal decisions, personnel actions, and compliance-critical processes, Microsoft advises that flows reach a human approval stage so people retain ultimate control. Treat an “Analysis failed” result—documented when instructions conflict or information is insufficient—as a deliberate stop or escalation condition, not permission to continue. See Microsoft’s multistage and AI approvals documentation.

Give reviewers enough context to make a real decision

A reviewer should be able to understand what approval will do without reconstructing the action from scattered records. Show the actual proposed operation and material parameters, the affected record or recipient, the relevant source context, the agent’s explanation, and the policy or threshold that applies. Identify uncertainty or missing information, and provide a way to inspect the relevant source record without exposing unrelated sensitive data.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Make the choices explicit: approving should authorize a clearly bounded action; rejecting should prevent it; requesting changes should send it back for revision; and escalation should identify the next responsible role. A bare prompt such as “Approve agent?” does not tell a reviewer what they are authorizing.

Pair approval with permissions, stop controls, and audit logs

Human review is one layer of control, not a substitute for safe system design. Use least privilege for the agent identity and its connectors; approval should not give the agent broader standing access than the task requires. Enforce prohibited actions with deterministic policy checks that do not depend on model output. Maintain a system-level pause or stop path, and govern model, tool, plugin, and data-source dependencies. These measures help limit the effects of prompt manipulation or an unexpected model response. Microsoft’s guidance covers reducing autonomous agentic AI risk and security and governance for agentic AI.

Log both the decision and what happened afterward. Include the proposed action, reviewer and decision, time, execution outcome, and any exception, along with enough policy context to understand why the gate applied. Protect logs according to the sensitivity of the information they contain. Microsoft recommends visibility into plans for higher-risk actions, progress and outcome summaries, and accessible action logs for audit and incident response. In Copilot Studio, its documentation describes viewing AI-stage inputs, decisions, and rationale in Power Automate history and prompt activity.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choose an implementation pattern that fits your environment

Consideration Agent SDK or runtime interruption Low-code multistage workflow
Best fit Engineering teams that control the agent runtime and tool wrappers Teams building agent flows in the Microsoft Power Platform environment
Enforcement point A protected tool call pauses the run; the decision is handled before the run resumes An approval action is inserted into the flow, which waits for assigned reviewers
Routing The application defines the approval interface and decision handling Manual stages, conditional routes, and documented platform approval channels
Nested execution SDK documentation describes run-wide interruptions across handoffs and nested agents Configured workflow stages coordinate steps in the flow
Important caveat API behavior is version-sensitive; consult current SDK documentation Multistage approvals are documented as preview and subject to change; AI stages require allocated Copilot Credits
Decision record The application must persist and expose the decision and run state appropriately Platform documentation describes approval history and visibility into AI-stage rationale

Choose based on who controls the runtime, existing workflow systems, reviewer channels, audit needs, tenant capability, and the team’s ability to test failure paths. The documented behavior and caveats are in the OpenAI SDK documentation, OpenAI API guidance, and Microsoft Copilot Studio documentation.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Pilot the workflow and check that the gate works

Begin with a bounded workflow, named owners, narrow permissions, and representative edge cases. Test the approval path as well as failure and abuse cases:

  • Approval, rejection, request for changes, and escalation.
  • Timeout, missing data, conflicting rules, and approval-service or tool failure.
  • Duplicate submissions and attempts to reach the same side effect through a different tool or rephrased request.
  • Whether any side effect occurs before authorization, and whether a rejected action can be retried without a new valid decision.

Measure reviewer time per item, correction rate by field or action, rejection rate, queue time, straight-through rate, and defects discovered after approval. If review takes nearly as long as manual processing, or reviewers approve without examining the content, improve the gate’s placement or the review surface. If defects survive review, the gate is not providing effective control. Microsoft’s runbook specifically calls attention to post-approval defects as a measure teams can overlook.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.