Skip to content
BotServBotServ
Human ApprovalHuman-in-the-LoopAI AgentSecurityConfirmationAutonomy

Human Approvals: Human-in-the-Loop for AI Agents

Why AI agents need human approvals: Human-in-the-Loop, confirmation mechanisms and safety measures explained.

S

schutzgeist

15 min read
Human Approvals: Human-in-the-Loop for AI Agents

Human Approvals: Human-in-the-Loop for AI Agents

What this article covers

  • What human approvals (human-in-the-loop) are and why they’re essential for AI agents
  • The different types of approvals, from pre-execution to batch approval, and when each makes sense
  • How to implement approvals in frameworks like LangGraph, CrewAI, and AutoGen
  • The different autonomy levels available and how to choose the right one for your use case
  • Common pitfalls, costs, and security considerations when using approvals

Introduction: Human approvals explained

AI agents are powerful. They search for information, write files, send emails, and access databases. But that power comes with risk. An agent acting independently can make mistakes that a human would never make. That’s why most agents need a mechanism to pause critical actions before execution and ask a human for confirmation. This is called human-in-the-loop, or human approval.

This article is for developers new to the concept who want to understand how human approvals work, when they’re useful, and how to implement them in practice. After reading, you’ll know the key terminology, the different approval types, common pitfalls, and the autonomy levels you can configure. You don’t need prior knowledge, just a basic understanding of what an AI agent is.

Why do you need human approvals?

Imagine you’ve built an autonomous agent to handle customer communications. It reads incoming emails, sorts them, and drafts replies. One day it misinterprets a complaint and sends an email to all your customers with the subject “We’re shutting down.” Without approvals, that email is already sent before you see it. The result: panicked customers, cancelled contracts, and damage you can’t undo.

Here’s another scenario: an agent is supposed to clean up old log files. It interprets “old” too loosely and deletes not just logs but your production database, thinking the entries are obsolete. Without approvals, your database is gone. Backups help, but the downtime costs time and money.

These aren’t theoretical scare stories. Agents hallucinate, they misunderstand instructions, they call tools with wrong parameters. The more autonomy an agent has, the greater the potential damage. Human approvals are the buffer that prevents a small mistake from becoming a disaster. They give you back control without making agents useless.

Human approvals in a nutshell

A human approval is a checkpoint where the agent pauses and asks a human for confirmation before executing an action. The human sees what the agent plans to do and decides: approve, reject, or modify. Only then does the action proceed.

Think of it like an everyday example: imagine a new employee who just started at your company. They can write emails and edit files on their own, but for purchases over 500 EUR they need their manager’s signature. They prepare the order, put it on their manager’s desk, and wait. The manager reviews it, signs off or rejects it. Only then is the order placed. That’s exactly how human-in-the-loop works with AI agents. The agent prepares the action, the human approves it, then it executes.

The difference between an agent with and without approvals isn’t what the agent can do, but when it’s allowed to do it. Without approvals, it acts immediately. With approvals, it pauses and waits for your okay.

Who should use human approvals?

Human approvals make sense for anyone deploying AI agents in real environments, not just in labs. Specifically:

  • Newcomers building their first agents and wanting to ensure nothing goes wrong before granting full autonomy
  • Teams running agents in production and needing to minimize liability risks
  • Decision-makers who need to understand what safety measures agents require before approving a rollout
  • Developers building agents for customers and needing to implement traceable approval steps

If you’re only experimenting and an agent runs in an isolated sandbox, you can skip approvals. But once the agent accesses real data, real systems, or real people, approvals aren’t a luxury anymore, they’re a necessity.

Key terms around human approvals

TermMeaning
Human-in-the-loopA human is integrated into the agent’s workflow and must confirm certain actions before they execute
ApprovalA human’s consent to a planned agent action, such as “send email to customer X”
ConfirmationSame as approval; the human confirms the action is allowed to execute
Autonomy levelThe degree to which the agent acts without human intervention, ranging from “confirm everything” to “fully autonomous”
ApprovalEnglish term for approval, used in many frameworks and documentation
VetoA human’s rejection of an action; the agent cannot execute it
EscalationWhen the agent cannot resolve a situation itself and passes it to a human, such as when data is unclear
TimeoutA deadline for the human to approve; if missed, the agent aborts or follows a fallback rule
Auto-ApproveA rule that automatically approves certain actions without human involvement, such as harmless web searches
GuardrailsSecurity rules that constrain the agent, such as “never delete files outside folder X”

Types of approvals

Not all approvals are the same. There are different ways a human can be integrated into the workflow. The most important ones:

Pre-Execution (approval before the action)

The agent plans an action, pauses, and asks the human: “Can I do this?” The action only runs after approval. This is the most common form and useful for actions that can’t be undone, such as sending emails, deleting files, or processing payments.

Example: the agent wants to send an email to all customers. It shows you the draft and recipient list. You click “Approve,” and only then is the email sent.

Post-Execution (review after the action)

The agent executes the action, logs it, and the human reviews it afterward. This makes sense for actions that are easy to undo or happen so frequently that pre-approval would block the workflow.

Example: the agent sorts incoming emails into folders. You review the sorting at the end of the day. If something’s wrong, you correct it. This is faster than approving every single email beforehand.

Conditional (Release Only at Risk)

The agent operates independently but pauses and asks for approval under specific conditions. You define these conditions, such as “release purchases over 500 EUR” or “release emails to more than 10 recipients”.

Example: The agent can trigger orders up to 500 EUR on its own. Above that threshold, it stops and requests your approval. This balances speed with safety.

Batch (Release Multiple Actions at Once)

The agent collects several actions and asks for a single approval to release them all. This works well when the agent performs many similar actions and requiring individual approvals would be cumbersome.

Example: The agent has drafted 50 emails. Instead of approving each one individually, you review all of them at once and release them together. You can filter out any you don’t want to send.

Which release method do you need?

The right approval strategy depends on how risky the action is and how often it occurs. Here’s a decision matrix:

ActionRiskFrequencyRecommended Release
Web searchlowhighAuto-approve, no release needed
Read filelowmediumAuto-approve, no release needed
Write filemediummediumPost-execution or conditional
Delete filehighlowPre-execution
Email to one personmediumhighPre-execution or conditional
Email to all customersvery highlowPre-execution, mandatory
Database query (read)lowhighAuto-approve
Database writehighlowPre-execution
Trigger paymentvery highlowPre-execution, mandatory
API call to external servicemediummediumConditional, depends on service

The rule of thumb: the higher the risk and the rarer the action, the more you need pre-execution. The lower the risk and the more frequent the action, the more post-execution or auto-approve will suffice.

Implementation in Frameworks

Most established frameworks support human-in-the-loop. Here’s how LangGraph, CrewAI, and AutoGen implement it. For a complete overview of frameworks, see Frameworks.

LangGraph

LangGraph, part of the LangChain ecosystem, offers so-called “interrupts”. The agent pauses at a specific node and waits for input. This works through a checkpointer that stores the state until the human responds.

from langgraph.graph import StateGraph
from langgraph.checkpoint.memory import MemorySaver

def send_email(state):
    # Agent drafts the email
    draft = state["draft"]
    # Interrupt: agent pauses here
    return {"draft": draft, "awaiting_approval": True}

def human_approval(state):
    # This is where approval is requested
    approval = input("Release email for sending? (y/n): ")
    if approval == "y":
        return {"approved": True}
    return {"approved": False}

graph = StateGraph()
graph.add_node("draft", send_email)
graph.add_node("approve", human_approval)
graph.add_edge("draft", "approve")

# With a checkpointer, the agent can pause and resume
app = graph.compile(checkpointer=MemorySaver())

The checkpointer is crucial. It preserves the agent’s state while waiting for approval. This lets you request approval asynchronously, for example through a web interface, without the agent continuing to run.

CrewAI

CrewAI works with “roles” and “tasks”. You can specify that a task requires human approval before the next step runs. This happens through the human_input parameter.

from crewai import Agent, Task, Crew

email_agent = Agent(
    role="Email Agent",
    goal="Create drafts for customer emails",
    backstory="A reliable assistant for customer communication.",
)

email_task = Task(
    description="Draft an email to customer Müller GmbH.",
    expected_output="An email draft with subject and body.",
    agent=email_agent,
    human_input=True,  # Requests human approval before completion
)

crew = Crew(agents=[email_agent], tasks=[email_task])
result = crew.kickoff()

With human_input=True, CrewAI pauses and asks the human for feedback or approval. It’s simpler than LangGraph but less flexible, since you can’t fine-tune the approval logic.

AutoGen

AutoGen from Microsoft uses “conversable agents”. You can define your own “UserProxy” agent that represents the human and requests confirmation for specific actions.

from autogen import ConversableAgent, UserProxyAgent

user_proxy = UserProxyAgent(
    name="Human",
    human_input_mode="ALWAYS",  # Always requests approval
)

assistant = ConversableAgent(
    name="Agent",
    system_message="You are an email agent.",
)

# Starts the conversation, the UserProxy asks for approval with each action
user_proxy.initiate_chat(assistant, message="Write an email to Müller GmbH.")

The human_input_mode controls how often you’re asked. ALWAYS asks every time, TERMINATE asks only at the end, NEVER never asks. For sensitive actions use ALWAYS, for harmless ones use NEVER or TERMINATE.

Example: An Agent with Approvals

Here’s a step-by-step example of an email agent that drafts messages but requires approval before sending.

Step 1: Receive the task. You tell the agent: “Write an email to customer Müller GmbH with the offer for project X.” The agent understands the goal and plans its steps.

Step 2: Fetch customer data. The agent reads customer information from the database, such as name, contact person, and recent communication. This runs without approval because it’s just a read operation.

Step 3: Create draft. The language model generates an email draft with subject, greeting, body, and signature. The draft sits in the agent’s memory.

Step 4: Request approval (pre-execution). The agent stops and shows you the draft. You see the subject, body, and recipient. You review: Is the text correct? Is the recipient right? Is the tone appropriate? You click “Approve” or “Reject”.

Step 5: Send email. Only after you approve does the agent send the email through the email tool. If you reject it, the draft stays in the agent’s memory and you can ask it to revise the text.

Step 6: Logging. The agent records the process: draft created, approval granted or denied, email sent or not. This way you can trace what happened.

This workflow combines autonomy with control. The agent does the work, you have the final say on the critical action. For more on agent planning and reflection, see Planning and Reflection.

Autonomy Levels

Not every agent needs the same number of approvals. There are five autonomy levels you can configure:

Full Auto (Complete Autonomy)

The agent operates fully independently, without approval or logging. It’s fast but risky. Only sensible for harmless tasks in isolated environments, such as an agent that analyzes data in a sandbox.

Auto with Logging

The agent acts independently, but each step is logged. You can review what happened afterward. This makes sense for frequent, lower-risk actions like sorting emails.

Conditional Approval

The agent acts independently, but at defined conditions it pauses and asks. This is the most common approach in practice because it balances speed and safety. Example: “Request approval for emails sent to more than 10 recipients.”

Full Approval

Every action requires approval. The agent prepares everything, you sign off on each step. Safe, but slow. Use this for highly critical tasks or when you’re new to an agent and haven’t built trust yet.

Manual Only

The agent plans and designs but executes nothing. You handle the execution. This isn’t really an agent anymore, it’s an assistant that makes suggestions. Useful when you need full control but want to benefit from the agent’s planning ability.

Which level you choose depends on your use case, the risk involved, and how much you trust the agent. Start with Full Approval or Conditional Approval, then gradually give the agent more autonomy as it proves itself.

Common Pitfalls with Human Approval

Approval sounds straightforward in theory, but practice reveals several traps. Here are the most common ones:

1. Too many approvals slow everything down. If every web search and file access needs approval, the agent becomes useless because you’re constantly confirming. Fix: Use Auto-Approve for harmless actions and Conditional Approval for risky ones.

2. Too few approvals risk errors. With no approvals, the agent can cause damage unchecked. Fix: Identify critical actions like sending emails, deleting files, or processing payments, and require approval for those.

3. Unclear approval criteria. If it’s not defined what needs approval and what doesn’t, developers decide ad hoc, which is inconsistent and error-prone. Fix: Document which actions require which approval type, ideally in a table.

4. No timeout handling. If the person never approves, the agent waits forever. Fix: Define a timeout after which the agent stops or applies a fallback rule, like “abort after 24 hours with no approval.”

5. Unclear who approves. In teams, it’s often undefined who’s responsible for which approval. Fix: Define roles, such as “finance approvals through accounting, email approvals through support lead.”

6. No good interface for approvals. If approvals happen via command line or unreadable logs, people make mistakes or ignore them. Fix: Use a clear interface that shows the plan, parameters, and consequences.

7. Approvals become routine. When people approve constantly, they eventually click “yes” blindly without checking. This makes approval pointless. Fix: Limit approvals to truly critical actions so each one matters.

Hardware, Costs, and Security with Human Approval

Hardware

Approvals themselves require little hardware. The agent pauses and waits, which costs no compute. What does require hardware is the interface through which approvals are granted. If you build a web app where people approve actions, it runs on a server. For local agents, you can request approvals via a simple desktop app or even the command line. More on local hardware in the article What is Local AI?.

Costs

Approvals cost no money directly, but they cost time. Each approval means a person must review the plan. With many approvals, this adds up. Cloud-based agents running while waiting can incur costs if the agent doesn’t pause cleanly. Make sure the agent stops making API calls during the approval phase.

Security

Approvals are themselves a security measure, but they must be secured. Who can approve? How is identity verified? Who logged what approval? These questions matter especially when approvals happen through a web interface. Use authentication, logging, and roles so not every user can grant approval. For more on security, see Agent Security and specifically Human Approval in Security.

FAQ: Human Approval - Common Questions

What exactly is Human-in-the-Loop?

Human-in-the-Loop means a person is part of the agent workflow and must confirm certain actions before they run. The agent prepares the action, the person approves it, then it executes. This prevents errors at critical steps.

Does every agent need human approval?

No. For harmless tasks in isolated environments, like data analysis in a sandbox, you don’t need approval. But once the agent accesses real data, systems, or people, approval for critical actions is recommended.

What’s the difference between Pre-Execution and Post-Execution?

Pre-Execution means the agent asks for approval before the action runs, which only happens after you agree. Post-Execution means the agent runs the action and you review it afterward. Pre-Execution is safer, Post-Execution is faster.

How do I prevent approval from becoming routine?

Limit approvals to truly critical actions. If people approve constantly, they click blindly. Use Conditional Approval so only risky actions need approval and harmless ones run automatically.

What happens if no one approves?

Without timeout handling, the agent waits forever. Define a timeout after which the agent stops or applies a fallback rule, like “abort after 24 hours with no approval and notify the responsible person.”

Which framework is best for approval?

LangGraph is most flexible because you can control interrupts and checkpointers precisely. CrewAI is simpler but less flexible. AutoGen is good for dialog-based approval. The choice depends on how much control you need.

Can I get approval asynchronously?

Yes. With a checkpointer like in LangGraph, the agent saves its state and waits. You can request approval via a web interface hours or days later, and the agent resumes as soon as approval comes through.

What is Auto-Approve?

Auto-Approve is a rule that automatically approves certain actions without human intervention. It makes sense for harmless, frequent actions like web searches or read access to files. This way you don’t get stuck on every small thing.

How do I specify who can approve?

Define roles and responsibilities. For example: “Finance approvals through accounting, email approvals through support lead.” In the interface, verify the approver’s identity and log who approved what.

Are approvals the same as guardrails?

No. Guardrails are automatic safety rules that restrict the agent, like “never delete files outside folder X.” Approvals are human checkpoints. Both complement each other: guardrails prevent gross errors automatically, approvals catch cases rules don’t cover.

Can approval stop the agent entirely?

Yes, if you veto. The person rejects the action, and the agent doesn’t execute it. Depending on the architecture, the agent either aborts the task or tries a different approach. This is useful when the planned action is wrong or risky.

Sources and Further Reading

  • LangGraph Documentation: Human-in-the-Loop
  • CrewAI Documentation: Human Input
  • AutoGen Documentation: UserProxy and Conversable Agents
  • Anthropic: Building Effective Agents
  • Microsoft: AutoGen and Human Approvals
Back to Blog
Share:

Related Posts