Tier the action, not the agent
Startrise designs AI agent approvals per action, not per agent: each action is auto-approved, run-and-notify, or blocked until a human signs off, decided by four questions. Here is the method on one page.
Both extremes fail: no gates, or a gate on everything
Fails loudly: one irreversible mistake, then the project is shelved.
Most actions flow; the consequential few wait for a human.
Fails quietly: taps become reflexive and the gate reviews nothing.
"Should a human approve this agent?" is the wrong question. An agent isn't trustworthy or untrustworthy; its individual actions are. "Draft a reply" and "issue a refund" can live in the same agent and deserve completely different supervision.
Three tiers, from free to expensive
Auto-approve
Reversible, internal, low-stakes. The agent acts and the log records it. Nobody is pinged.
Notify
Act now, tell the human immediately. No pause, no reply expected; a human can undo it.
Block-and-ask
Nothing happens until a named human says yes. Expensive by design, so keep it small.
Four questions assign the tier
Can you undo it in one step?
If not, start one tier higher than instinct says.
Does it reach outside the team?
Customers or production data turn mistakes into incidents.
Does it move money or sensitive data?
Payments, PII, credentials, contracts: block-and-ask by default.
Can a human keep up at this frequency?
If not, a gate is fiction. Switch to sampling and rollback.
What a tiered policy looks like
| Action | Tier | Channel | Fallback |
|---|---|---|---|
| Draft a support reply (not sent) | Auto | Log only | n/a |
| Update an internal wiki page | Notify | Slack message | Human reverts |
| Send an email to one customer | Block-and-ask | Slack approval | Fail closed, escalate |
| Issue a small refund | Block-and-ask | Telegram buttons | Fail closed, escalate to finance |
| Tag hundreds of inbound leads a day | QA sampling | Dashboard | Batch rollback |
Illustrative example, not client data. Adapted from our approval-workflow guide.
A good approval request shows four things and fails closed
1 · Action: Send reply to one customer
2 · Why: Ticket asks for an order-status update
3 · Exact inputs: recipient, subject, full body
Silence is its own outcome. On a block-and-ask action, no reply means no action, and the request escalates to a second human instead of quietly expiring. Every request and decision lands in an audit log.
At volume, sample instead of gating
Our editorial-network build runs on spot-check QA gates and batch rollback, not per-item review. In the case study's words: "at this volume you don't proofread posts, you manage failure rates."
Source: Startrise editorial-network case study.
Getting it built
This framework is how we configure every agent. AI Agents That Act starts from $3,500, with a 2–4 week timeline, approval gates and an audit log included. Code-first? Our open-source ping-a-human MCP server gives an agent notify_human and ask_human over Telegram.
Sources
- startrise.io/blog/ai-agent-approval-workflow/ (source article, July 2026)
- startrise-web src/content/portfolio/editorial-network.md (volume figures)
- startrise-web src/data/subservices.js (price, timeline)