Prompt
I'm building an agent that needs approvals before writing to systems, what should I use?
Latest observation
Oct 9, 2026
OpenAI APIWeb search: off
If your agent needs human approvals before it can write to external systems, the best pattern is usually:
Use an approval workflow / human-in-the-loop gate
What that means
Before the agent performs any side-effecting action (write, delete, send, deploy, update), it:
- Drafts the action
- Presents it for approval
- Waits for a human to approve / reject / edit
- Only then executes the write
Recommended implementation pattern
Design your agent so it separates:
- Read-only reasoning/tools
e.g. search, fetch, inspect, summarize - Proposed actions
e.g. “update record X”, “create ticket Y”, “send email Z” - Approval checkpoint
a UI, queue, Slack/Teams message, or workflow step - Execution tool
only callable after approval
Good options depending on your stack
1. Workflow engine with approval steps
Best if you need reliability and auditability.
- Examples: Temporal, Camunda, Airflow (less ideal for interactive approvals)
- Pros: retries, state, audit trail, long-running approvals
- Good for: enterprise automation
2. Agent framework with human-in-the-loop hooks
Best if you’re already building LLM agents.
- Use a framework that supports:
- tool gating
- interrupt/resume
- human approval nodes
- Good for: agentic apps where plans are generated dynamically
3. Custom approval queue
Best for simpler systems.
- Agent creates a proposed action object
- Store it in DB
- Notify approver
- On approval, a worker executes it
- Good for: straightforward internal tools
Key design principle
Never let the model directly call write tools without a policy check.
Instead, enforce:
- allowlist of safe read tools
- approval required for write tools
- strong logging of:
- who approved
- what was approved
- when it ran
- exact payload
Practical recommendation
If you want a robust, production-friendly setup:
- Use a workflow engine for state/approval
- Use the agent only to propose actions
- Require human approval before any write
- Add an idempotency key to avoid duplicate writes
- Keep a full audit log
Example flow
- Agent determines: “Update customer status to active”
- Agent outputs a structured proposal
- Human reviews in UI/Slack
- Approver clicks “Approve”
- System executes the update
- Result is logged and returned to agent/user
If you tell me what stack you’re using, I can suggest the best specific tool or architecture for it.