Approvals and a stop switch for AI agents

An approval queue that fits in a few minutes a day, and a stop that halts an AI agent from a phone in about thirty seconds.

An approval step protects a company only while the person approving reads each request. Once the queue outgrows that person's time, requests go through unread. Ben Green's 2022 review of 41 policies that require human oversight of government algorithms concludes, from the research evidence, that people are generally unable to perform the oversight those policies expect (Computer Law and Security Review, 2022). The design on this page keeps requests few and quick to judge, under a minute each, and puts the stop switch on a phone.

How an approval queue goes quiet

Invented for illustration: an agent drafts 60 customer replies a day for a four-person landscaping company. In the first week the office manager opens each card and edits about one in five. By the fourth week the queue arrives at 5 p.m., the cards go through in a run of taps, and the edit count reads zero.

Raja Parasuraman and Dietrich Manzey's 2010 review of the research found that automation bias affects novices and experts alike, and that training or instructions do not prevent it (Human Factors, 2010, abstract). Green reaches the same point from the policy side and proposes that any form of human oversight an agency relies on be backed by empirical evidence that it works.

What an approval card holds

The card in this guide carries enough to decide without opening anything else.

Part of the cardWhat it holdsWhat it lets the reader do
The actionOne line: what will happen, and to whomJudge the act before the wording
The exact contentThe email, the file or the amount, in fullApprove what goes out, word for word
The reasonWhat triggered it and which instruction it followedTell a sensible request from a confused one
The evidenceLinks to the records the agent relied onCheck a claim in one tap
The reachWho receives it, what changes, whether it can be undoneSee the size of a mistake before it happens
The costWhat this item cost to produce, if knownSpot an expensive request
Three answersApprove, edit, or reject with a short reasonAdd to the task's record

The edits and rejections on these cards are also the record that decides whether a task moves up a level (how levels are earned).

Batches, and the requests that travel alone

A batch holds requests of the same kind built from the same kind of input, such as ten appointment confirmations drawn from one calendar. The person reads the batch as one list and answers it once. Anything unusual comes out of the batch and waits on its own card.

Some requests reach a person whatever the task's level. The Open Worldwide Application Security Project, a nonprofit, calls for a person's approval before high-impact actions, and for authorization checked in the downstream systems instead of left to the model's judgment (Excessive Agency, 2025). This guide adds one more trigger: a request the agent fails to understand twice goes to a person.

When the agent speaks to customers

On February 14, 2024 the Civil Resolution Tribunal of British Columbia decided Moffatt, a dispute over a bereavement fare (the tribunal's decision). An airline's website chatbot had told the customer that a reduced bereavement rate could be claimed within 90 days, even after travel, which the airline's own bereavement page did not allow. The airline argued it could not be held liable for what its chatbot said. The tribunal described that as treating the chatbot as a separate legal entity, rejected it, held the airline responsible for all the information on its website and ordered it to pay the customer damages.

The decision is Canadian, and this guide is general information, not legal advice. Each new kind of statement an agent makes to customers, such as a fare rule or a refund window, goes through approval until the agent has a clean record on that kind of statement.

A stop built before it is needed

The stop switch in this design:

  • It only stops. Pressing it halts work, and nothing on the same screen starts work, so a slip of the thumb cannot make things worse.
  • It comes in two sizes. One stops a kind of action, such as all sending. The other stops the agent.
  • A phone reaches it in about thirty seconds. A stop that lives on the office computer is out of reach on a job site.
  • It leaves work in a safe state. Invented for illustration: an agent stopped while booking a five-person meeting has sent two invites, and a note written in advance tells those two people the meeting may not happen.
  • The agent cannot block it. The switch sits outside anything the agent can change, delay or turn off.

The AI Risk Management Framework from the National Institute of Standards and Technology asks for assigned responsibility and mechanisms to supersede, disengage or deactivate an AI system whose results stray from its intended use (Manage 2.4). The European Union's AI Act provides that the people overseeing a high-risk AI system be able, as appropriate and proportionate, to interrupt it through a stop button or a similar procedure that brings it to a halt in a safe state (Article 14). Under a 2026 amendment, the Act's rules for high-risk systems in areas such as employment apply from December 2, 2027 (European Commission). Outside the European Union, its stop-button wording is a usable spec.

A week before the agent goes live, someone presses the switch in a scheduled test and reads the receipts for anything sent after the press. The same test runs each month after that.

Weeks with nobody at the queue

When requests wait past a set limit, the agent stops adding new outside work and holds at draft. Without that limit, requests pile up through a week away and get approved in a hurry on the first day back.

Where an approval step gives way

  • Approval with nobody reading. Edits and rejections at zero for weeks fit two stories: the task has earned a level up on its record, or nobody is reading the cards. The tally alone cannot tell them apart.
  • A gate the agent can walk around. An agent with no refund right can still draft an email asking the office manager to issue a refund. Narrowing what the agent can send, and to whom, closes that path. How an attacker plants a harmful request in the queue is a security question, outside this site.

The worksheet

The agent readiness worksheet has a checklist for approval cards and another for the stop switch.

Sources

All sources were read on September 27, 2026.

Talk through one agent workflow

A 30-minute call about one agent workflow: what it may do alone and who approves the rest. Bring the step you most want to hand off.

Book a 30-minute callRead the guides

Booking opens Google Calendar in a new tab.