Prompt
How do I add human approval before an agent sends emails?
Latest observation
A good way to do this is to insert a human-in-the-loop approval step right before the email-sending tool runs.
Typical pattern
-
Agent drafts the email
The agent composes the subject/body and maybe recipient list. -
Pause before execution
Instead of sending immediately, the system creates an approval request. -
Human reviews and approves/rejects
A person sees the draft in a UI, Slack, email, or dashboard. -
Only then send
If approved, your backend calls the actual email API; if rejected, the agent revises or stops.
Practical ways to implement it
Option 1: Tool wrapper with approval gate
Wrap your send_email tool so it never sends directly. It returns a pending approval object:
{
"status": "pending_approval",
"draft": {
"to": "user@example.com",
"subject": "Follow-up",
"body": "Hi ...",
"attachments": []
}
}
Then your app:
- stores the draft,
- notifies a human,
- waits for approval,
- and only then invokes the real email sender.
Option 2: Agent workflow with a “human approval” node
If you use an orchestrator/workflow graph, add a node between:
- Draft email
- Approve/reject
- Send email
This is often the cleanest approach for production systems.
Option 3: Model decides, but cannot execute
Give the agent permission to prepare a “send email request,” but not direct access to the provider credentials. The backend enforces the approval requirement.
Key safeguards
- Never let the LLM hold raw send credentials
- Log the draft and approval decision
- Show recipient, subject, and body clearly
- Expire pending approvals after a timeout
- Require re-approval if the draft changes
- Optionally auto-approve low-risk emails only if your policy allows it
Example flow
- Agent: “I’ve drafted an email to Alice.”
- System: stores draft and marks it
pending_approval - Human: clicks Approve
- Backend: sends email via API
- System: marks message as sent and logs the action
If you’re using a specific framework
Many agent frameworks support this via:
- interrupt / pause hooks
- human approval callbacks
- tool execution middleware
- workflow state transitions
If you tell me what stack you’re using—e.g. OpenAI Agents SDK, LangChain, LangGraph, AutoGen, Temporal, or a custom backend—I can show you an exact implementation.