How does a human-approval gate actually work?
Mechanically, it's simple. Somewhere in the agent's workflow there's a step that says: stop here, show a human what you're about to do, and do nothing until they say yes. Concretely: the agent monitors your inbox, drafts a reply to each new inquiry using your rules and your tone, and drops the draft into a queue. You get a notification, read the draft, and tap approve — or edit it, or kill it. Only then does it send. The agent did ninety percent of the work; you supplied the two seconds of judgment.
In one of our own builds — a prospecting agent that identifies likely customers from licensed data and prepares direct mail (still in build; the status label is honest) — the gate sits right before the mail goes out. The system can research, filter, and draft all day on its own. It cannot put a single letter in the post without a human reviewing the batch. That's a design decision, not a technical limitation: the gate could be removed in five minutes. It won't be, because every letter carries the company's name.
The placement rule: the agent can do anything reversible on its own — reading, sorting, researching, drafting. Anything irreversible — sending, posting, paying, mailing — goes through the gate. Reversible is free; irreversible costs a human click.
Why not just trust the AI if it's usually right?
Because "usually right" is exactly the problem. An agent that's wrong half the time gets caught immediately and fixed. An agent that's right 97% of the time earns your trust, gets ignored, and then sends its 3% mistake to your best customer.
AI mistakes also aren't like human mistakes. A tired employee writes a sloppy email. An AI system can confidently state a price you don't charge, promise a delivery date that doesn't exist, or misread a complaint as a compliment — fluently, politely, in your brand voice. The mistakes read plausible, which makes them more dangerous than obvious errors, not less. And then there's scale: when you make a mistake, you make it once; an unattended agent can make the same mistake forty times before breakfast. The gate converts "forty wrong emails sent" into "forty wrong drafts caught in a queue" — the difference between an incident and a non-event.
None of this argues the technology is bad. It argues that judgment and labor are different things, and a first agent should automate the labor while you keep the judgment. That division is what makes it safe to start at all — and it's why we won't sell unsupervised "AI employees".
Doesn't approving everything defeat the point of automation?
It's the most common objection, and the math says no. Take lead follow-up. Without an agent: notice the inquiry whenever you next check email, work out what they're asking, write a reply from scratch, remember to follow up — fifteen or twenty minutes of scattered attention per lead, and the after-hours ones wait, sometimes until they've hired someone else. With a gated agent: read a finished draft, tap approve. Seconds, not minutes, and nothing waits until morning to be drafted — only to be approved.
Approval also gets cheaper as trust accumulates. After a few weeks of clean drafts, many owners choose to auto-approve the lowest-risk category — acknowledgments, say — while keeping the gate on quotes and anything with a price in it. The point is that loosening the gate becomes a decision you make from evidence, not a hope you start with.
How do you spot a vendor who skipped the gate?
Ask three questions. Where does the human approve? If the answer is a blank look or "the AI handles it," walk. What happens when the agent is uncertain? The right answer is "it flags and stops," not "it figures it out." Can I see the approval step in the design? In every system we deliver it's drawn on the architecture diagram in amber — visible, named, non-negotiable. A vendor who treats the gate as an embarrassing limitation is selling you an incident on a delay.