Two agents, one limit, one refused.
All guides
Approvals
Updated
2 min read
by Anlyon Team

How to bind human approval to the action an AI agent executes

Prevent approval substitution: show the exact operation, bind its target and version, check freshness, and separate a decision from a verified outcome.

human in the loopapproval bindingtool versioning

Approve the actual operation, not just its summary. The request executed after approval must match the amount, destination, resource and version the reviewer saw. Persist those values and verify the binding again at dispatch. A changed request needs a new review.

Consider a reviewer shown “refund $20 to order 42.” An approval flag is insufficient if mutable state can later change the amount to $200 or the destination to another account. This approval-substitution failure is called loopjacking in a September 2026 paper that reproduced it on LangGraph Agent Server and Agno AgentOS (arXiv 2609.21081). The useful engineering question is whether the executed request can differ from the reviewed one.

What a reviewer needs to see

FieldWhy it matters
Environment and target accountPrevent reviewing a test action that dispatches elsewhere
Exact resource and normalized requestMake the amount, recipient or file change explicit
Action and adapter versionsBind the decision to the definition being executed
Provider state and observation timeDistinguish a current constraint from an earlier observation
Expiry and impactBound review lifetime and show allowance consumption
Success conditionExplain which provider evidence will establish completion

Anlyon's governed-effect previews store this information and a binding digest. The dispatcher recomputes the digest from the persisted effect. A mismatch refuses dispatch. Refreshing a preview creates a new binding. An old approval does not transfer.

Binding and freshness are different

A request can be unchanged while the world has changed. The GitHub file-update adapter sends the reviewed blob SHA, so a concurrent file change can be rejected atomically. The Stripe refund adapter's preview shows the refundable balance as of review. Read the per-adapter guarantees.

Dispatch also checks current policy, environment halt, requester revocation and remaining impact capacity. Approval is permission to attempt the reviewed operation under those checks.

Avoid turning oversight into a rubber stamp

Route clearly allowed low-impact work through deterministic policy, deny forbidden work, and escalate operations that need judgment. Keep the review payload concrete. Do not let the model invent reviewer identity, approve its own request, or replace a structured preview with persuasive prose.

Measure approval volume and decision latency in your own deployment. A shorter queue is useful only if the policy still covers the consequential operations. No escalation rule guarantees an attentive reviewer.

What the binding covers

The binding mechanism applies to governed effects. With a local approval wrapper, Anlyon records the decision and your process runs the function. An approval records the decision, and provider evidence establishes the outcome.

Evaluate with a supported test action · Tool-selection guide · Current beta limits

Frequently asked questions

How do I stop an approved tool call changing before it runs?

Persist the exact reviewed operation, bind the approval to it, and refuse dispatch if the request, target, version or expiry no longer matches. For Anlyon governed effects, previews bind those values and the dispatcher recomputes the binding before sending.

What does the approval digest cover?

The digest binds the reviewed request, target, versions, preconditions and expiry to dispatch. Anlyon recomputes it before sending and refuses on any difference.

Free tier, no credit card. One command if you use Claude or Cursor.

$ claude mcp add anlyon -- npx -y @anlyonhq/mcp-server