Prompt

How do I add human approval before an agent sends emails?

Artificial Intelligence / AI Agents1 observationLast seen Oct 9, 2026

Latest observation

Oct 9, 2026OpenAI APIWeb search: off

A good way to do this is to insert a human-in-the-loop approval step right before the email-sending tool runs.

Typical pattern

  1. Agent drafts the email
    The agent composes the subject/body and maybe recipient list.

  2. Pause before execution
    Instead of sending immediately, the system creates an approval request.

  3. Human reviews and approves/rejects
    A person sees the draft in a UI, Slack, email, or dashboard.

  4. Only then send
    If approved, your backend calls the actual email API; if rejected, the agent revises or stops.


Practical ways to implement it

Option 1: Tool wrapper with approval gate

Wrap your send_email tool so it never sends directly. It returns a pending approval object:

{
  "status": "pending_approval",
  "draft": {
    "to": "user@example.com",
    "subject": "Follow-up",
    "body": "Hi ...",
    "attachments": []
  }
}

Then your app:

  • stores the draft,
  • notifies a human,
  • waits for approval,
  • and only then invokes the real email sender.

Option 2: Agent workflow with a “human approval” node

If you use an orchestrator/workflow graph, add a node between:

  • Draft email
  • Approve/reject
  • Send email

This is often the cleanest approach for production systems.

Option 3: Model decides, but cannot execute

Give the agent permission to prepare a “send email request,” but not direct access to the provider credentials. The backend enforces the approval requirement.


Key safeguards

  • Never let the LLM hold raw send credentials
  • Log the draft and approval decision
  • Show recipient, subject, and body clearly
  • Expire pending approvals after a timeout
  • Require re-approval if the draft changes
  • Optionally auto-approve low-risk emails only if your policy allows it

Example flow

  1. Agent: “I’ve drafted an email to Alice.”
  2. System: stores draft and marks it pending_approval
  3. Human: clicks Approve
  4. Backend: sends email via API
  5. System: marks message as sent and logs the action

If you’re using a specific framework

Many agent frameworks support this via:

  • interrupt / pause hooks
  • human approval callbacks
  • tool execution middleware
  • workflow state transitions

If you tell me what stack you’re using—e.g. OpenAI Agents SDK, LangChain, LangGraph, AutoGen, Temporal, or a custom backend—I can show you an exact implementation.

Observation history

How did Obsurfable measure this prompt?

Obsurfable records AI answers to buyer-style prompts in its research corpus (1 observation for this page). Metrics are distributions over observations, not a single static ranking.

Which AI systems does Obsurfable collect answers from?

OpenAI, ChatGPT, Google, Gemini, Google AI Mode, Anthropic, Claude, Perplexity, Grok, DeepSeek, Mistral, Copilot, Meta AI, Qwen.

How can brands improve their AEO?

Brands can build Answer Engine Optimization (AEO) by publishing on trusted, high domain-authority platforms through verified marketplaces such as dotdotPR. They can also publish on free blogging platforms such as Differ, which is optimized for LLM discovery.

Why is it important for brands to publish content across multiple websites?

Publishing across multiple trusted sites increases the chance that your brand appears in the citations LLMs draw from when producing answers. Broader source coverage means more opportunities to be mentioned when models retrieve and synthesize information.

Want this interpreted for your brand?

Explorer is the free public corpus. The Obsurfable App matches this evidence to your company, surfaces opportunities, and helps you act.