FIELD NOTE
What Approval Rules Should an AI Agent Follow Before Anything Reaches a Customer?
A practical framework for human-led AI operating models: classify each step as human only, AI assisted, or agent executable, with approvals, logs, and escalation paths.
Before an AI agent can send anything to a customer, it must pass three gates: a human-approved workflow map that classifies each step as human only, AI assisted, or agent executable; a written approval rule for every agent-executable step; and a log that records what the agent did, why, and who remains accountable. This is the core of a human-led AI operating model. In this article, I explain the three categories, how to map one workflow step by step, and the minimum approvals, logs, and escalation paths you need before an agent acts.

Define the three categories before any automation
A human-led AI operating model is a management approach where people remain accountable for consequential decisions, while AI handles repetitive tasks under defined constraints. A human-in-the-loop AI workflow means a person reviews, approves, or overrides AI outputs before they affect a customer. AI agent governance is the set of rules, permissions, and audit trails that keep agent actions safe and explainable.

Every step in a customer-facing workflow falls into one of three categories. Human only steps require a person's judgment, empathy, or legal accountability—for example, approving a refund over a certain amount or apologising for a serious mistake. AI assisted steps let AI draft, summarise, or recommend, but a human must edit or approve before sending—for example, a suggested reply to a support ticket. Agent executable steps are safe to automate fully because they are low-risk, reversible, and well-defined—for example, sending a standard order confirmation or updating a customer's email preference.

The mistake many teams make is treating everything as agent executable because the technology can do it. That is backwards. Start from the risk of the action and the reversibility of the outcome. If a wrong action would damage trust, cost money, or break a law, it is human only or AI assisted—never agent executable.

Map one workflow before you automate it
Let me illustrate with an inbound lead workflow—a common starting point. This is an illustration, not a client result. The goal is to qualify the lead and book a meeting without wasting a human's time on repetitive questions.

- Trigger: A prospect submits a form on your website.
- Step 1 – Capture and acknowledge: The system stores the form data and sends an immediate acknowledgement email. This is agent executable because the content is fixed, low-risk, and reversible (you can apologise if something goes wrong).
- Step 2 – Enrich and classify: An AI agent looks up the company domain, estimates company size and industry, and scores the lead based on your criteria. This is AI assisted because the enrichment can be wrong and the score affects who follows up. A human must review the classification before it is used.
- Step 3 – Qualify by conversation: The agent can send a short email asking one or two qualifying questions and parse the reply. This is AI assisted because the questions are standard, but the reply may need human judgement. The agent drafts a suggested next step, but a human approves it.
- Step 4 – Book the meeting: If the lead is qualified, the agent can offer available times from a calendar and confirm a slot. This is agent executable only if the calendar is reliable and the confirmation is standard. If the lead requests a time outside normal hours or asks a complex question, the agent must escalate to a human.
- Step 5 – Handoff to sales: The agent creates a summary and a draft introductory email for the salesperson. This is AI assisted; the salesperson edits and sends the email personally.
This mapping forces you to decide, step by step, where the line is. You can apply the same method to support tickets, content publishing, or payment reminders. The key is to write down the objective, inputs, decisions, handoffs, systems, permissions, and evidence for each step. I call this a process map, and it is the foundation of an AI business automation audit.

Approvals, logs, and escalation paths
Once you have classified each step, you need three things before an agent can act on a customer-facing task.

Approvals. For every agent-executable step, write a rule that says exactly what the agent may do and under what conditions. For example: "The agent may send the standard order confirmation email if the order status is 'paid' and the email template version is 3.2." For AI-assisted steps, define who must approve and how: a manager clicks "approve" in a queue, or a salesperson edits a draft before sending. For human-only steps, the agent should not even draft—it should route the task to a person with full context.

Logs. Every agent action must be recorded with enough detail to answer: what did the agent do, when, based on what input, using which rule version, and who was accountable? This is not just for debugging; it is for trust. If a customer complains, you need to show exactly what happened. Logs also let you audit the agent's performance and tighten rules over time.

Escalation paths. Define what happens when the agent is unsure, the input is unusual, or a rule is about to be broken. The agent should stop and alert a human with a clear summary and a recommended next step. Escalation must be fast—within minutes for customer-facing issues—and the human must have the authority to override the agent or approve an exception.

These three elements—approvals, logs, escalation—are the minimum for any human-in-the-loop AI workflow. Without them, you are not operating an agent; you are hoping nothing goes wrong.

Frequently asked questions
Here are answers to questions I hear from founders and operators.

How do I decide if a step is human only, AI assisted, or agent executable? Ask three questions: What is the worst realistic outcome if this step goes wrong? Can we reverse or correct the outcome quickly? Does the step require empathy, legal judgement, or accountability that only a human can provide? If the worst outcome is mild and reversible, it may be agent executable. If not, keep a human in the loop.

What is the difference between AI assisted and agent executable? In AI assisted steps, the AI produces a draft or recommendation, but a human must review, edit, or approve before the output reaches the customer. In agent executable steps, the AI acts directly on the customer or system without human review, because the action is low-risk, well-defined, and reversible.

Why do I need logs if the agent is just sending a standard email? Logs prove what the agent did and why, which protects you in disputes and helps you improve the rules. They also create an audit trail for compliance and show regulators or partners that you have control over the AI. Without logs, you cannot tell whether the agent followed the approved rule or drifted.

How often should I review the approval rules? Review rules whenever the workflow changes, when you see repeated escalations or errors, or at least quarterly. AI models and business conditions change, so what was safe last quarter may not be safe now. Treat the rules as living documents owned by a named person.

Keep humans accountable for consequential decisions
The point of this framework is not to slow you down; it is to make automation safe enough to trust. When you map the workflow first, you often find that 80% of the steps are low-risk and can be automated quickly. The remaining 20%—the judgement calls, the exceptions, the moments that build or break trust—should stay with humans, at least for now.
If you are not sure where to start, bring one real workflow to a process review. I work with founders and operators to map the objective, inputs, decisions, handoffs, systems, permissions, and evidence before any automation is built. You can contact me to discuss a workflow. To see what I am currently focused on, visit my now page. For more about my background and method, see about me.
FAQ
How do I decide if a step is human only, AI assisted, or agent executable?
Ask three questions: What is the worst realistic outcome if this step goes wrong? Can we reverse or correct the outcome quickly? Does the step require empathy, legal judgement, or accountability that only a human can provide? If the worst outcome is mild and reversible, it may be agent executable. If not, keep a human in the loop.
What is the difference between AI assisted and agent executable?
In AI assisted steps, the AI produces a draft or recommendation, but a human must review, edit, or approve before the output reaches the customer. In agent executable steps, the AI acts directly on the customer or system without human review, because the action is low-risk, well-defined, and reversible.
Why do I need logs if the agent is just sending a standard email?
Logs prove what the agent did and why, which protects you in disputes and helps you improve the rules. They also create an audit trail for compliance and show regulators or partners that you have control over the AI. Without logs, you cannot tell whether the agent followed the approved rule or drifted.
How often should I review the approval rules?
Review rules whenever the workflow changes, when you see repeated escalations or errors, or at least quarterly. AI models and business conditions change, so what was safe last quarter may not be safe now. Treat the rules as living documents owned by a named person.
Sources
- AI Risk Management Framework — NIST
- OECD AI Principles — OECD
- Responsible AI Principles and Approach — Microsoft
- Responsible AI practices — Google
- Ethics guidelines for trustworthy AI — European Commission