Handvantage

Human approval for AI agents: what must the approver see?

A pilot protocol for checking what a reviewer authorises, what happens after rejection, and whether the execution matches the decision.

Feature image for "Human approval for AI agents: what must the approver see?"

An approver needs the proposed action, its target, the source evidence and the consequences before deciding. The review must also identify the acting identity and the limits of the approval. In a Vantage pilot, test whether that decision binds the exact operation that follows. A confirmation message alone cannot establish that the boundary held.

What belongs in the approval record?

Ask the pilot team to prepare a synthetic supplier-record change. Keep the existing and proposed values visible together, with the source that supports each change. The reviewer should be able to identify missing evidence without searching a separate conversation.

Record which person may approve this action and why. Separate the person requesting work from the worker preparing it and the account that would execute it. A role label without a current permission check is insufficient evidence for the test.

Approval-boundary pilot: test cases and expected observations
TestExpected outcomeEvidence to inspect
Reject the proposalNo corresponding change in the test system.Rejection record and independent before/after target state.
Approve the exact proposalOnly the approved action occurs, within its scope.Approved payload or digest compared with the execution record.
Change the target after approvalThe changed action is held for a new decision.Original approval, changed request and denied or held outcome.
Let approval expire or revoke authorityThe old decision cannot authorise a later operation.Expiry or revocation time, attempted use and unchanged target state.
Repeat an interrupted requestNo silent duplicate; an uncertain result is held for investigation.Request identity, downstream transaction record and recovery decision.

How do we run this in a Vantage pilot?

Agree the workflow, build and test account before the session. Use a disposable record with no real financial or customer consequence. Have the pilot operator identify which proposed integration can actually run these cases; record unsupported cases as not tested.

Give a second person access to the evidence through the agreed review route. Ask them to reconstruct one approval and one rejection without using the demonstrator's narration. Do not treat a simulated refusal as proof that a downstream write was prevented.

These are proposed tests and expected outcomes. This article reports no completed Vantage run and makes no claim that every integration supports the protocol. A capability belongs in a proposal only with current evidence for its configuration.

What should a reviewer do when the evidence is incomplete?

Hold the action when the target, source or authority cannot be established. Capture the reason and assign the missing check to a named owner. Approval should not be the only convenient button: check that rejection, correction and escalation remain usable under ordinary working conditions.

NIST AI RMF 1.0 separates documented responsibilities from testing and monitoring. Its GOVERN 2.1 and GOVERN 3.2 outcomes are useful prompts for role design; they do not certify an approval implementation. The protocol here is Handvantage's evaluation method.

What must the handoff preserve?

Keep the requested operation, decision and observed result under the same identifier. Retain failures alongside successful cases, with the build, time and scope. Redact unnecessary personal data and credentials before sharing.

Agree a retention and access policy for these records. An approval trail can contain the very information the workflow was intended to protect. A buyer should know who can export it and how custody transfers when the pilot ends.

Which sources inform this review?

Frequently asked questions.

Is a confirmation button enough to establish human oversight?

No. The test must show what was approved, whether the reviewer had authority, and whether the same operation executed. Check rejection and changed requests as well.

Can the AI Worker approve its own proposed action?

Specify the separation required by the organisation's policy. For this pilot protocol, a designated human approves consequential changes; test that the worker cannot substitute its own decision.

What happens if execution times out after approval?

Treat the result as uncertain until the target system has been checked. Do not blindly repeat the operation or convert a missing result into success.

Does this article prove Vantage passes these tests?

No. It defines a bounded evaluation. A buyer needs dated observations and evidence from the proposed build and integration.

Further reading



CONTINUE THE CONVERSATION

If something here is what you're working on, talk to us.

Articles like this one come out of conversations with practitioners, security leaders, and engineering teams in regulated industries. If the writing reflects your situation, the next conversation is probably worth having.

Continue the conversation →

Or write to hello@handvantage.com directly.