Skip to content
HUMAN IN THE LOOPUPDATED 2026-09-29

Human approval for AI agents

THE SHORT ANSWER

Human-in-the-loop approval means an AI agent can prepare an action but cannot complete it until an authorised person says yes. Done properly, the rule is enforced by the platform rather than written into a prompt: the action is stopped at the moment it would run, the approver is a named role, the person who asked cannot approve their own request, and every decision is recorded.

Which actions should wait for a person

Not every step needs a human — that would make agents useless. The line is consequence: actions that are irreversible, that leave the organisation, or that someone outside will rely on.

  • Money moving: releasing a payment batch, authorising a settlement.
  • Communication outside: a notice to a borrower, a message to a patient or customer.
  • Production change: promoting a database replica, isolating a host, changing access.
  • Deletion or disclosure of records.

What makes an approval real

  • Enforced where the action executes — a prompt that says “ask first” is advice to a model, not a control.
  • Named approver roles, not “anyone who is online”.
  • Quorum when it matters: two of three treasury approvers, for example.
  • Separation of duties: the person who requested or prepared the action does not count towards its approval.
  • The approval is for this exact action and these parameters — approving a draft is not approving a different payment.
  • Expiry and escalation, so a request nobody answers does not wait for ever — and never runs by default.
  • Delegation with a time window, for holidays and cover, recorded like any other grant.
  • Fail closed: if the platform cannot confirm an approval, the action does not run.

What the approver should see

The action and its parameters, the evidence the agent relied on, and why the policy asked for a person. An approver shown only “Approve?” is being asked to trust the agent, which defeats the purpose.

Common mistakes

  • Asking the model to request permission instead of enforcing it.
  • Letting the requester approve their own action.
  • Approving a category (“payments”) instead of an action (“this batch”).
  • Keeping no record of who approved what, and when.
HOW A2A MATRIX DOES IT
  • Approval chains per company and department, with quorum, separation of duties and time-boxed delegation.
  • Overdue approvals expire on a governed schedule; an unanswered action never runs.
  • A workflow step waiting for approval resumes only after the engine re-reads the decision and confirms it says approved.
  • Every decision — who, when, under which rule — is appended to the company’s tamper-evident ledger.
See it decide on six real examples
QUESTIONS

Asked often.
Answered plainly.

Isn’t a system prompt telling the agent to ask first enough?+

No. A prompt is guidance to a model and can be ignored or overridden. The check has to happen where the action executes, independent of what the model says.

Can one person approve their own request?+

Not when separation of duties is set: the requester is excluded from their own quorum, so a second authorised person must decide.

What happens if nobody approves?+

The request expires or escalates under your policy. The action never executes by default.

Does every action need an approval?+

No. Reading, analysing and preparing run on their own; only the actions your policy marks as consequential wait for a person.