When an automation should ask a human for approval.
Use explicit approval gates for external messages, publishing and irreversible changes.
Identify risky actions
Flag actions that contact customers, publish public content, alter sensitive records or move money. Choose approval rules based on impact, not novelty.
Show reviewers enough context
Present the proposed action, source links, relevant fields and a clear approve/reject choice. Do not expose unnecessary personal data.
Make approval enforceable
The workflow must pause before the protected action and resume only after a valid approval event. A note saying 'review this' is not a control.
Plan timeout and rejection
Define who gets notified, what happens if the reviewer does not respond and how rejected work returns to an owner.
Audit decisions
Record reviewer identity, decision, timestamp and workflow version. Test unauthorized approval, repeated approval events and expired requests.
Use the toolkit
Turn this advice into a structured workflow, then test it with synthetic data before production.