Skip to content

Topic

Human approval gates on irreversible actions

A design pattern in AI agent systems requiring human sign-off before irreversible actions like deletions, payments, or permission changes.

Current stories

leadership1 publisher

Anduril CMO gives his AI agent access to email and bank details, but keeps the final yes for himself

Anduril marketing chief Jeff Miller gave AI agents access to his bank details and email, then used them to clear six months of expense reports. The approval he keeps for himself covers what an agent sends or buys, so a team policy modelled on it still has to decide what the agent may read.

Reality

Evidence35
Adoption20
Hype gap+35
Incentives60
Confidence40
build1 publisher

Move execution authority out of the model and into the tool boundary

A dev.to design note inserts code gates and a human approval between the model and the tool, which is the right shape, though a policy layer that reads a severity field the model itself wrote has not moved the authority anywhere.

Publishers:dev.to

Reality

Evidence30
Adoption
Insufficient
Hype gap+22
Incentives20
Confidence45

Earlier coverage

  1. Let the agent propose, not commit: the envelope that has to arrive before a write

    Build · August 24, 2026 · 1 publisher

  2. Prompt injection has no parameterized query, so stop shopping for a sterner system prompt

    Build · August 23, 2026 · 1 publisher

  3. One state machine or two: the transaction fork hiding inside your MCP server

    Build · August 23, 2026 · 1 publisher

  4. A self-healing scraper that must prove its repair against twelve records that cannot move

    Build · August 22, 2026 · 1 publisher

  5. A £40 refund and a £40,000 one look identical to a pre-execution guardrail

    Build · August 21, 2026 · 1 publisher

  6. UiPath bets your bottleneck is trust, not code. Audit your maintenance bill first

    Product · August 20, 2026 · 1 publisher

  7. The bug in your multi-agent system is not the model, it is the open HTTP request

    Build · August 16, 2026 · 1 publisher

  8. Your first MCP workflow should be a draft queue, not an agent with keys to the inbox

    Build · August 16, 2026 · 1 publisher

  9. Prompt injection is a permissions problem wearing a prompt engineering costume

    Build · August 14, 2026 · 1 publisher