Guide · Updated 18 September 2026 · 5 min read

Human in the loop for AI agents: what a good approval looks like

Approval is where autonomy meets accountability. Five properties of an approval that people actually read, and how Harmona builds them in.

Every vendor now says "human in the loop". The phrase covers everything from a confirmation dialog nobody reads to a real decision point with the facts on the table. Here is what separates the two, and how Harmona builds approvals so people keep reading them.

Why approvals fail

Approvals fail in two directions. Too many, and people click through them; the control exists on paper and nowhere else. Too few, and an agent sends a customer the wrong number at 03:00. The fix is not "more approvals" or "fewer approvals"; it is putting the approval exactly where the risk changes class: at the moment something leaves your systems.

Five properties of an approval people read

  1. It shows the exact action. Not "send e-mail?" but the recipients, the subject, the account it goes from, and the body. Harmona's approval card lists the fields of the action as they will be executed.
  2. It is the only step that waits. Reading, refreshing, analysing and drafting run on their own. Only outbound actions (mail, ticket updates, CRM changes, messages to a channel, files written to a drive) stop for a person, so each card means something.
  3. It arrives where the person already is. In a Worker, the card is in the chat. In a workflow, it lands in the inbox of the right person with an expiry. Nobody has to open a separate console.
  4. It has two outcomes and a record. Approve or decline; nothing else. Either way the decision stays in the transcript with the tool calls around it, so the log reads like a history, not a chat.
  5. It is the same everywhere. A Worker, an agent with tools and a workflow use the same card. People learn it once.

What about work that runs while nobody is watching?

Scheduled tasks are where "human in the loop" usually breaks, because there is no human at 06:00. Harmona handles this with permissions granted at creation: when you delegate a task, you approve a list of what it may do, from "set reminders" to "reply through Zoho Desk". The run keeps to that list, declines anything outside it, and reports what it declined to your inbox. The approval happened once, in advance, and it is enforced every run.

Approving changes to the system itself

The same rule applies when the thing being changed is an agent or a workflow. In Agent Mode, every change, from adding a step to sharing an agent with a colleague, is a gated change. They are batched into one card per turn, written in plain language, and nothing is applied until you approve. No delete tools exist in the builder at all.

Questions to ask any vendor

Does the approval show the exact payload? Which actions wait and which do not? Where does the approval arrive? Does it expire? Is the decision in the audit trail? How do scheduled runs get permission? Can an agent widen its own permissions? The answers tell you whether "human in the loop" is a control or a slogan.

Tomorrow is a long time in AI. Start today.

Every week without a Worker is a week of work you did by hand. Create a workspace today and have your first one running before your next meeting.

14-day free trial · No credit card · 2,000 credits included