Protocol

Put approval immediately before the high-impact action

Approval at the start of a long plan is not approval of the action the plan eventually invented.

When it fits

  • An agent can send, delete, publish, purchase, merge, transfer or otherwise create consequential external effects.

When to avoid it

  • Human approval can become a rubber stamp if prompts are frequent, vague or hide relevant consequences.

Why it matters

Insert human approval at the boundary where the consequential action is fully specified. Show the target, important parameters and expected effect. After approval, execute that bounded action rather than giving the agent blanket permission for whatever comes next.

Steps

  1. The reviewer can tell what will change before accepting the action.

An example

Before an agent merges a pull request, show the repository, branch, PR, checks and exact merge operation rather than asking for generic 'GitHub access.'

Check your result

The reviewer can tell what will change before accepting the action.

Keep this limit in mind

  • Human approval can become a rubber stamp if prompts are frequent, vague or hide relevant consequences.

Connected ideas

Useful with
Enforce permissions outside the model

Evidence and sources

Supports

OWASP recommends human approval before high-impact agent actions are taken.

Approval is useful only when the reviewer can see the consequential action and relevant context rather than clicking through a vague confirmation.

LLM06:2025 Excessive Agency · Require user approval

All sources (1)