
AI agent approval workflows: review the action before it runs
Design human review for sensitive tool calls, bind approval to the exact request, and handle retries without confusing permission with execution.
The decision in brief
Effective approval has a precise subject, an authorized reviewer, and a limited lifetime. In Durin, a different administrator approves one exact request; the requester then retries it before expiry. Permission and execution remain separate events.
Choose the right kind of human review
Human-in-the-loop means a person can review or intervene in an agent’s proposed action. It can include a client confirmation, independent review, or an operational checkpoint. These mechanisms provide different levels of separation and enforcement.
The MCP tools specification recommends user visibility and confirmation for sensitive operations. Durin adds independent review when its write policy requires it: another active administrator decides whether a specific request may proceed.
Decide which actions need approval
Use the consequences of an action to guide review. An illustrative external message, bulk update, or payment can merit more scrutiny than a low-sensitivity lookup. Read-only tools can still disclose confidential information, so access checks remain necessary.
Treat these as risk-assessment examples, not built-in Durin risk tiers. Durin’s current policy editor controls default access and the organization’s write decision. Team restrictions can make those controls stricter; it is not an arbitrary per-tool rule builder or an approver-routing engine.
- Impact: what data, money, or external communication could change?
- Scope: how many records or recipients could one call affect?
- Reversibility: how would you detect and repair a mistake?
- Review quality: does the reviewer have enough context to make a decision?
Required checks come before approval
Durin first checks identity, membership, connection and team access, credentials, reviewed tools, resources, and inspection results. An approval cannot repair a failed mandatory check or expand upstream provider permissions.
Default allow applies only after required checks pass. Administrators can require another administrator for writes or deny writes entirely; default deny blocks tool access. Sandbox and production use the same policy controls.
An unreviewed tool stays blocked pending tool review. Reviewing a tool definition and approving a particular write are separate decisions.
Bind the approval to the request
An exact grant covers the requester, organization, connection, credential context, tool and schema versions, resource, argument digest, policy version, and revocation state. Changing that context can invalidate the approval.
The argument digest is a fingerprint used to match the request; it is not a readable description of the operation. Durin’s review shows that digest alongside the requester, tool, resource, policy and schema versions, and expiry. Reviewers need the relevant business context before approving.
Grants expire and are single-use. Membership and authority are checked again before execution, so earlier approval does not preserve access after revocation.
Follow the request through approval and retry
Use a supported sandbox write, a permitted fixture resource, and two different administrators to test the lifecycle. Confirm each stage before moving to the next.
- Submit the write under a policy requiring approval and confirm that no upstream action ran.
- Have the other administrator open Approvals and review the exact request.
- Approve the request and confirm that approval alone did not execute it.
- Retry the identical call before expiry, with the authorization context still valid.
- Inspect the execution outcome; test refusal, expiry, and changed arguments with separate fixture requests.
Handle uncertainty without duplicating a write
A connection can fail after an upstream system has committed a change. No response does not mean no action. Approval, dispatch, and confirmed completion must remain distinct.
Durin records required execution intent before a governed write and does not automatically repeat a potentially completed write. Inspect the recorded outcome and reconcile it with the provider before deciding whether a new action is appropriate.
Single-use approval limits reuse of the grant; it is not a universal exactly-once guarantee across external systems. Include uncertain outcomes in your runbook and assign an owner to reconcile them.