As AI agents gain access to email, browsers, files, business systems and payments, teams need a simple approval policy that explains when an agent may act alone and when a human must approve the action. A good policy is specific enough to enforce but simple enough for users to understand.
Start with action risk
Not every agent action needs the same level of review. Reading a public page is different from deleting a file, sending an external email or moving money. Group actions by impact rather than by the model that performs them.
A practical four-level approval model
| Level | Example | Control |
|---|---|---|
| Low | Read public information | Agent can act |
| Medium | Create a draft | Log action |
| High | Send external communication | Human approval |
| Critical | Payment or destructive change | Explicit approval and strong authentication |
Define who can approve
Approval should not be an anonymous button. For business workflows, identify the person or role that can authorize the action and keep a record of the decision.
Keep approval separate from the model
The model should propose an action. A policy layer should check the user's permission, action type, target and limits. The model should not be able to rewrite the policy that governs it.
What the audit record should contain
Record the agent identity, request, selected tool, policy result, approver where required, timestamp and final outcome. Avoid logging passwords, access tokens or unnecessary private data.
How to test the policy
- Test normal low-risk actions.
- Test a high-risk action with approval.
- Test an approval denial.
- Test a timeout or network failure.
- Test an agent trying to bypass a restriction.
Why simple rules are better
Complex policies become hard to maintain. Start with a small number of action categories, then add detail only where real risk justifies it. Every exception should have an owner.
Related ToolBoxKart guides
Use How to Audit AI Agent Permissions, AI Agent Audit Logs, AI Agent Architect, and Vibe Coding vs Agentic Coding to build the wider workflow.
Frequently asked questions
Does every agent action need human approval?
No. Low-risk actions can often run under predefined rules. Approval should match the impact of the action.
Should approval happen inside the model?
No. Keep authorization in a separate policy layer that the model cannot change.
What should be logged?
Log identity, tool, target, policy decision, approval state, timestamp and outcome without storing unnecessary secrets.