The approval step: letting AI do real work without losing control

How to design the human review that lets AI do real work: what needs a yes, how to keep the review fast and when to loosen it.

There’s one rule in every AI system I build: anything published, sent, spent or promised needs a person to say yes first. In Gridwork, nothing ships until you approve it. People sometimes read that as caution, or as a lack of faith in the technology. It’s the opposite. The approval step is what lets you hand AI real work in the first place. Without it, you either don’t trust the system enough to use it, or you trust it too much and find out the hard way. This is the playbook I use to design one that stays fast, and to loosen it without losing control.

What needs a yes, and what doesn’t

Four verbs cover almost everything that needs approval.

  • Published. Anything the public can see: posts, pages, ads, replies to reviews.
  • Sent. Anything that lands in someone else’s inbox or phone: emails, follow-ups, messages to customers, partners or candidates.
  • Spent. Anything that moves money: budgets, bids, purchases, refunds, discounts.
  • Promised. Anything that commits you: prices, dates, terms, what the product will do.

Most other work can run without a gate. Research, drafts, summaries, internal notes, tagging and sorting are where the hours go, and they’re what you want AI doing freely.

Watch for hidden sends, though. Updating a CRM record can trigger an automated email. Editing a product page can change a price. If an action sets off something that is published, sent, spent or promised, treat it as one.

When you’re not sure, ask two questions. Can it be undone? How many people will see it? The harder it is to undo, and the more people see it, the more it needs a person.

“If it leaves the building or can’t be undone, a person says yes.”

Make the review take seconds

An approval step only works if people do it properly. If reviewing is slow, it becomes a bottleneck. If it’s tedious, it becomes a rubber stamp. Either way, you’ve lost the point of having it. Here’s what keeps it fast.

  • Show the real thing. The actual email or the actual ad, exactly as it will appear. Not a description of it.
  • Show the why beside it. What triggered the work, which sources it used and anything it wasn’t sure about.
  • Offer three choices. Approve, edit or reject. A rejection needs a reason, picked from a short list, so patterns show up later.
  • Batch it. Review in a few set sittings a day, not one item at a time as they arrive.
  • Meet reviewers where they work. Approvals should arrive in the tools people already check, so a yes takes a tap, not a login.
  • Route it to the right person. The one who’d answer for it if it went wrong, not whoever happens to be free.
  • Treat silence as a no. If nobody reviews it, it waits. Nothing should go out because the reviewer was busy.

Keep every edit, too. The gap between what the AI drafted and what a person approved is the most useful feedback you’ll get, because it shows you where the brief is unclear.

Start tight, then loosen

Every new workflow starts at the bottom and earns its way up. I think of it as four steps.

  1. Suggest. The AI drafts. A person takes the action.
  2. Approve. The AI prepares the action. A person approves each one.
  3. Approve the exceptions. The AI handles routine cases on its own. Anything unusual goes to a person: a new customer, a large amount, a sensitive topic, an answer it isn’t confident about. Someone still spot-checks a sample of the rest.
  4. Report. The AI acts within set limits and reports what it did. A person reviews the log.
Diagram: a four-step ladder rising from Suggest to Approve, Approve the exceptions and Report. Beside it, a note listing work that never climbs past Approve: large spends, prices, contracts and key customers.
Autonomy is earned one workflow at a time, and it can always step back down.

A few rules for moving between steps:

  • Move one workflow at a time, never the whole system.
  • Move up when approvals stop changing anything. If you’ve been saying yes without edits for weeks, the step has become friction.
  • Move down straight after a real mistake, and find out why before you move up again.
  • Some work never climbs past step two: spending above a set limit, prices, contracts, anything legal and anything going to your most important customers.

Underneath every step sit hard limits that apply no matter who is reviewing: a budget cap, a list of who can be contacted, a ceiling on how many messages go out in an hour and a list of topics that always go to a person.

If you’re choosing where to start, pick replies to new enquiries. They’re repetitive, easy to measure and quick to review.

Here’s how that workflow might climb. At first, the AI drafts and you send. Then it prepares each reply and you approve it. Once your edits dry up, routine questions go out on their own, while anything touching a price, a discount or an unhappy customer still comes to you. You may never need to go further than that, and that’s fine.

Log what you’d need after a mistake

Every action should leave a trail a person can read. For each one, record:

  • what the AI produced, and what it was working from
  • who approved it, and when
  • what they changed, or why they rejected it
  • what happened next: the reply, the click, the complaint

The log does three jobs. It shows who said yes, which matters when something goes wrong. It shows where the brief needs work, because edits tend to cluster around the same few problems. And it gives you evidence for raising autonomy, or lowering it, based on what actually happened rather than how anyone feels.

Where approval steps go wrong

The same few failures come up again and again.

  • One approver for everything. Usually the founder. Work piles up and the whole system looks slow. Give each workflow its own owner.
  • Approving a summary. If the reviewer only sees what the AI says it did, they’re approving a description, not the work.
  • A queue too long to read. Faced with a long list every morning, people stop reading and start clicking. Batch it, sample it and move routine work up a step.
  • Rejections nobody reads. The reasons pile up in the log, but nobody updates the brief. Read them every week and fix the instructions, or the same mistakes keep coming back.
  • Never loosening. An approval that hasn’t changed anything in a month isn’t protecting you. It’s slowing you down.
  • Loosening everything at once. One good week isn’t a track record.

Your first approval step

If you’re setting one up for the first time, grab the free notes from my AI agents for marketers workshop. They walk through a sensible first agent and the guardrails around it, built on the same rule: nothing goes out until a person says yes.

Written by MuddaaFounder of Gridwork, Momentem, Leila and Onshow. 11+ years in marketing, tech and AI.
Get the next one in your inbox.One email a week. Notes from the build, no spam.