Short answer
Place approval by reversibility. Work that only you see needs none. Anything a customer, a regulator or a bank will see needs a person before it goes. Anything that moves money needs a person every time. Start stricter than feels necessary and relax it on evidence, never on enthusiasm.
Key takeaways
- Reversibility, not confidence, decides where the human sits.
- Four tiers: internal drafts, outward-facing, irreversible, and money. Money never becomes automatic.
- Approval fatigue is a real failure: if a person rubber-stamps 200 items a day, you have supervision on paper only.
- Move an approval point only after weeks of clean output, and move it for one slice at a time.
Every demo shows the send step, because the send step is the exciting one. In a live business the send step is the one that costs you a client. The design question is not whether a human is involved, it is exactly where they stand, and the answer follows from how hard it would be to undo the mistake.
The four tiers
Internal preparation that only your team sees: let the agent run. Anything that will be read by a customer or posted publicly: the agent prepares and a person sends. Anything irreversible, such as deleting records or changing a live configuration: confirm every time. Anything that moves money: a person decides, always.
| Tier | Examples | Who approves | Can this ever become automatic? |
|---|---|---|---|
| Internal only | Meeting notes, drafts, research, reconciliation prep | Nobody, review by sampling | Already is |
| Outward facing | Client emails, proposals, posts, review replies | A named person, before it sends | Only on narrow, proven slices |
| Irreversible | Deletions, live config changes, scheduling changes | A named person, every time | No |
| Money | Payments, refunds, discounts, purchases | A person, every time | No |
Why start stricter than you need to
Because the first weeks are when you learn what the agent does with cases you did not anticipate, and that is cheap to learn at the draft stage and expensive to learn in a client inbox. Strictness early also buys trust from the team, which is what makes the second and third agents possible.
Approval fatigue is a design failure
If a person has to approve two hundred items a day, they will approve them without reading, and you have supervision on paper with none in practice. When volume gets there, either narrow what the agent handles, or split the queue so only exceptions reach a human while routine items pass under a sampled review.
- Sample rather than approve, once volume is high and quality has held for weeks.
- Route by confidence: the agent flags what it is unsure about, and that queue gets real attention.
- Cap the batch: an approval queue with no limit is a queue nobody reads.
- Track the correction rate. A rate near zero means either excellent work or rubber-stamping, and you need to know which.
How to move an approval point safely
- Pick the narrowest slice of the work with the lowest stakes, not the whole workflow.
- Require several weeks of output where corrections were rare and none of them were serious.
- Let the agent act on that slice alone, while everything else still goes through approval.
- Watch it for another few weeks, with the correction rate visible to whoever owns the agent.
- Write down what happened, so the next decision is made on a record rather than a feeling.
The line that does not move
Money. Not because the software cannot do the arithmetic, but because the failure mode is a confident, complete, wrong transaction, and because accountability for it has to sit with a person. Let code compute the number and a human authorise it. That rule has never cost us anything worth having.
Questions people ask
Can an agent send client emails on its own?
Eventually, on narrow and proven slices, and not at the start. Outward-facing work should be agent-prepared and human-sent until you have weeks of clean output. A wrong email to a client of record is not a bug report, it is a relationship.
How do I stop approval becoming a bottleneck?
Narrow the work, route by the agent’s own confidence so only uncertain items need attention, cap batch sizes, and move to sampled review once quality has held. A queue nobody reads is worse than no queue, because it looks like control.
Should agents ever touch money?
They can prepare the work: assemble the reconciliation, flag the exception, draft the invoice. The authorisation stays with a person every time. Let code calculate the figure and a human approve the movement.
Who should be the approver?
A named individual who owns the outcome, not a department and not whoever is free. Named ownership is the single strongest predictor of whether an agent is still running well in month six.
What do I do when the agent makes a mistake?
Record it, find whether the cause was a missing rule, a missing example or a changed process, and fix that rather than the individual output. Fixing outputs one at a time teaches you nothing and the same mistake returns next week.
Sources
- delegAIte AI Workforce Deployment deliverables, delegaite.co (read 20 September 2026): Human-in-the-loop controls and agent governance as part of the standard install rather than an option.
Published . Last reviewed .
Want this in your business?
Book a call and we will scope exactly which part of your operation an agent should take first.
Book a call with the team