AI Agent Approval Workflow
An AI agent approval workflow pauses an agent right before a risky action so a person can approve, reject, or edit it before anything actually runs.
This page is the map: what the workflow looks like end to end, the decisions that shape one, and links to the specific use case closest to what your agent does.
When you need one
Not every agent action needs a person in the loop. You need an approval workflow when an agent can trigger something hard to undo — sending a message, spending money, changing a record, shipping code — and the content or target of that action is generated rather than fixed. A read-only agent that only summarizes data doesn't need this. An agent that drafts a refund, a deploy, or an outbound email does, because a bad draft executed at machine speed is a bad draft that already happened. What is human-in-the-loop for AI agents covers the underlying reasoning in more depth.
How it looks in practice
The shape is always the same three steps, regardless of what the agent does:
- Propose. The agent pushes the action it wants to take — a draft, a query, a request — with enough context for a human to judge it, instead of executing directly.
- Decide. A person sees the proposal in an inbox and approves it, rejects it, or edits the draft first. Nothing runs until this happens.
- Execute. The agent picks up the decision and only then performs the real side effect, using the human-approved (and possibly edited) version.
This is the propose → approve → execute pattern — see the propose-approve-execute pattern for the mechanics and how to add human approval to an AI agent for the three-call integration over REST or MCP.
Agent Gate Human
│ │ │
├── propose action ───────────▶ stores it, notifies ──────────▶ inbox card
│ │ │
│ │◀── approve / reject / edit ────┤
├── read decision ─────────────┤ │
│ │ │
└── execute (only if approved) │ │Decision points that shape a workflow
Four choices turn the generic pattern above into a workflow that fits your agent:
- What to gate. Gate the actions that are hard to reverse or costly to get wrong — sends, spend, deploys, deletes — not everything the agent does. Gating read-only or fully reversible steps just adds latency for no safety gain.
- Timeouts and expiry. A pending decision shouldn't wait forever, and an approved-too-late decision shouldn't execute against stale context. See handling approval timeouts and expiry in agents for how long to set an action's expiry per kind of action.
- Escalation and auto-decisions. Not every action needs a human every time. A rules engine can auto-approve low-stakes matches, auto-reject known-bad patterns, or route specific kinds to a named channel, so people only see what actually needs judgment — see the rules engine.
- Audit trail. Once a decision is made, who made it and when needs to be recorded somewhere nobody can quietly edit afterward — see building an audit trail for AI agent actions.
Approval workflows by use case
The pattern above is the same everywhere; what changes is what gets gated and what the reviewer needs to see. Pick the page closest to your agent:
Coding and infrastructure
- Approve AI agent GitHub Actions workflows — gate a workflow file or dispatch an agent proposes before it runs in CI.
- Human-in-the-loop CI/CD for AI agents — the broader pattern for gating build and deploy steps an agent triggers.
- Human-in-the-loop for AI agent DNS and infra changes — approval before an agent touches DNS records or infrastructure config.
- Gate destructive database operations from an AI agent — a human sees the actual statement before a write or schema change touches production.
- Get human approval into your coding agent — wiring the gate into Claude Code, Cursor, Codex, or Windsurf specifically.
Communication and content
- Human approval for AI social media management — review a post before it goes out under your account.
- Approve AI-generated content before it publishes — the same gate applied to blog posts, docs, and marketing copy.
- Human-in-the-loop for AI customer support — approve a support reply before it reaches a real customer.
Money and operations
- Approval workflow for AI marketing automation — sign-off on a campaign or ad spend change before it goes live.
- Approve AI agent payments and charges — a human confirms the amount and recipient before money moves.
- Human-in-the-loop for AI agent incident response — approval on the remediation step an agent proposes during an incident, not on the diagnosis.
Background reading
- Human-in-the-loop, explained — the concept without the implementation details.
- HITL tools for LLM agents, compared — how a dedicated approval gate differs from a workflow engine or a Slack bot you'd build yourself.
How Impri implements this
Impri is the gate in the middle of that diagram, not the agent and not the execution step. An agent calls POST /v1/actions with a preview of what it wants to do; a human sees a card in a web, Slack, Discord, or Telegram inbox and approves, rejects, or edits it; the agent polls or receives a webhook and executes only on approval, then reports the outcome back. Rules can auto-decide routine matches before a human ever sees them, and every step — created, rule-applied, decided, executed — lands in an append-only audit log. Impri never executes the action itself and doesn't judge whether a decision was the right call; it holds the queue and the record. Start with quickstart for an API key, or how to add human approval to an AI agent for the full integration.