An approval step protects a company only while the person approving reads each request. Once the queue outgrows that person's time, requests go through unread. Ben Green's 2022 review of 41 policies that require human oversight of government algorithms concludes, from the research evidence, that people are generally unable to perform the oversight those policies expect (Computer Law and Security Review, 2022). The design on this page keeps requests few and quick to judge, under a minute each, and puts the stop switch on a phone.
How an approval queue goes quiet
Invented for illustration: an agent drafts 60 customer replies a day for a four-person landscaping company. In the first week the office manager opens each card and edits about one in five. By the fourth week the queue arrives at 5 p.m., the cards go through in a run of taps, and the edit count reads zero.
Raja Parasuraman and Dietrich Manzey's 2010 review of the research found that automation bias affects novices and experts alike, and that training or instructions do not prevent it (Human Factors, 2010, abstract). Green reaches the same point from the policy side and proposes that any form of human oversight an agency relies on be backed by empirical evidence that it works.
What an approval card holds
The card in this guide carries enough to decide without opening anything else.
| Part of the card | What it holds | What it lets the reader do |
|---|---|---|
| The action | One line: what will happen, and to whom | Judge the act before the wording |
| The exact content | The email, the file or the amount, in full | Approve what goes out, word for word |
| The reason | What triggered it and which instruction it followed | Tell a sensible request from a confused one |
| The evidence | Links to the records the agent relied on | Check a claim in one tap |
| The reach | Who receives it, what changes, whether it can be undone | See the size of a mistake before it happens |
| The cost | What this item cost to produce, if known | Spot an expensive request |
| Three answers | Approve, edit, or reject with a short reason | Add to the task's record |
The edits and rejections on these cards are also the record that decides whether a task moves up a level (how levels are earned).
Batches, and the requests that travel alone
A batch holds requests of the same kind built from the same kind of input, such as ten appointment confirmations drawn from one calendar. The person reads the batch as one list and answers it once. Anything unusual comes out of the batch and waits on its own card.
Some requests reach a person whatever the task's level. The Open Worldwide Application Security Project, a nonprofit, calls for a person's approval before high-impact actions, and for authorization checked in the downstream systems instead of left to the model's judgment (Excessive Agency, 2025). This guide adds one more trigger: a request the agent fails to understand twice goes to a person.
When the agent speaks to customers
On February 14, 2024 the Civil Resolution Tribunal of British Columbia decided Moffatt, a dispute over a bereavement fare (the tribunal's decision). An airline's website chatbot had told the customer that a reduced bereavement rate could be claimed within 90 days, even after travel, which the airline's own bereavement page did not allow. The airline argued it could not be held liable for what its chatbot said. The tribunal described that as treating the chatbot as a separate legal entity, rejected it, held the airline responsible for all the information on its website and ordered it to pay the customer damages.
The decision is Canadian, and this guide is general information, not legal advice. Each new kind of statement an agent makes to customers, such as a fare rule or a refund window, goes through approval until the agent has a clean record on that kind of statement.
A stop built before it is needed
The stop switch in this design:
- It only stops. Pressing it halts work, and nothing on the same screen starts work, so a slip of the thumb cannot make things worse.
- It comes in two sizes. One stops a kind of action, such as all sending. The other stops the agent.
- A phone reaches it in about thirty seconds. A stop that lives on the office computer is out of reach on a job site.
- It leaves work in a safe state. Invented for illustration: an agent stopped while booking a five-person meeting has sent two invites, and a note written in advance tells those two people the meeting may not happen.
- The agent cannot block it. The switch sits outside anything the agent can change, delay or turn off.
The AI Risk Management Framework from the National Institute of Standards and Technology asks for assigned responsibility and mechanisms to supersede, disengage or deactivate an AI system whose results stray from its intended use (Manage 2.4). The European Union's AI Act provides that the people overseeing a high-risk AI system be able, as appropriate and proportionate, to interrupt it through a stop button or a similar procedure that brings it to a halt in a safe state (Article 14). Under a 2026 amendment, the Act's rules for high-risk systems in areas such as employment apply from December 2, 2027 (European Commission). Outside the European Union, its stop-button wording is a usable spec.
A week before the agent goes live, someone presses the switch in a scheduled test and reads the receipts for anything sent after the press. The same test runs each month after that.
Weeks with nobody at the queue
When requests wait past a set limit, the agent stops adding new outside work and holds at draft. Without that limit, requests pile up through a week away and get approved in a hurry on the first day back.
Where an approval step gives way
- Approval with nobody reading. Edits and rejections at zero for weeks fit two stories: the task has earned a level up on its record, or nobody is reading the cards. The tally alone cannot tell them apart.
- A gate the agent can walk around. An agent with no refund right can still draft an email asking the office manager to issue a refund. Narrowing what the agent can send, and to whom, closes that path. How an attacker plants a harmful request in the queue is a security question, outside this site.
The worksheet
The agent readiness worksheet has a checklist for approval cards and another for the stop switch.
Sources
All sources were read on September 27, 2026.
- Ben Green, The flaws of policies requiring human oversight of government algorithms, Computer Law and Security Review, volume 45, article 105681, 2022, open access.
- Raja Parasuraman and Dietrich H. Manzey, Complacency and Bias in Human Use of Automation: An Attentional Integration, Human Factors, volume 52, issue 3, 2010, full text behind the publisher's paywall; free abstract at the Transport Research International Documentation record.
- Open Worldwide Application Security Project, Gen AI Security Project, Excessive Agency, 2025 list of risks for large language model applications.
- Civil Resolution Tribunal of British Columbia, Moffatt, 2024 decision 149, February 14, 2024, on the tribunal's own decisions site.
- National Institute of Standards and Technology, AI Risk Management Framework 1.0, core functions, January 2023, subcategory Manage 2.4.
- European Union, Regulation 2024/1689 (the AI Act), Article 14, human oversight, paragraph 4, point (e), text published by the European Commission's AI Act Service Desk.
- European Commission, AI Act, Shaping Europe's digital future, the Commission's page on the Act and its 2026 amendment, which entered into force on July 27, 2026.
