Trust & Safety

Why AI Should Ask Permission Before It Acts

12 August 20265 min read
ShareX / TwitterLinkedIn

Ask a business owner what worries them about AI and it's rarely the technology failing. It's the technology succeeding at the wrong thing: an email sent to a customer that shouldn't have gone, a price quoted wrongly, a record changed without anyone noticing. The fix isn't less capable AI. It's a deliberate line between what AI does alone and what it must ask about first — and the discipline to draw that line in the right place.

Gates Guard Actions, Not Documents

A principle we apply to every workflow we build: approval gates belong on actions, not on documents. If the AI produces something read-only — a research brief, a summary, a triaged inbox — it should simply deliver it. Making a human approve a document they're about to read anyway adds friction and trains people to click yes without looking. But the moment a workflow is about to act — send the email, issue the quote, update the customer record — it stops, shows a human exactly what it wants to do, and waits.

A no-stakes approval is worse than none: it teaches people to rubber-stamp. Reserve the gate for the moments that matter, and the click stays meaningful.

What a Good Approval Moment Looks Like

Done properly, an approval request shows the complete action, not a summary of it: the exact email, the actual recipient, the full text — delivered where your team already works, with one click to approve and one to reject. No logging into another system, no reconstructing context. The human applies the judgement; the machine has already done the labour. Ten seconds of review buys certainty that nothing reaches a customer without a person having seen it.

Actions that should wait for a human, at least at first:

  • Anything sent to a customer or prospect — email, SMS, quote, invoice
  • Anything that changes money — payments, refunds, pricing
  • Anything that changes records other people rely on — CRM updates, cancellations
  • Anything irreversible — deletions, submissions to third parties

Trust Is Transferred, Not Assumed

Gates aren't permanent by default — they're a dial. In every deployment we run, everything customer-facing starts gated. The team watches the AI's drafts for a while, corrects the tone, rejects the odd one. Then something shifts: the drafts stop needing edits, and approving starts to feel like ceremony. That's the moment to remove the gate from that workflow — deliberately, one workflow at a time, on evidence rather than hope. Trust transfers through observed behaviour. There is no shortcut, and there shouldn't be.

The question to ask any AI vendor isn't 'how clever is it?' It's 'show me the moment it asks permission — and show me how I decide when it stops needing to.' If they can't, keep looking.

Ready to deploy your AI agent?

Our engineers connect your systems and build workflows like these for you — live in five working days, supported from then on.

Book a discovery call