How to bind human approval to the action an AI agent executes
Prevent approval substitution: show the exact operation, bind its target and version, check freshness, and separate a decision from a verified outcome.
Approve the actual operation, not just its summary. The request executed after approval must match the amount, destination, resource and version the reviewer saw. Persist those values and verify the binding again at dispatch. A changed request needs a new review.
Consider a reviewer shown “refund $20 to order 42.” An approval flag is insufficient if mutable state can later change the amount to $200 or the destination to another account. This approval-substitution failure is called loopjacking in a September 2026 paper that reproduced it on LangGraph Agent Server and Agno AgentOS (arXiv 2609.21081). The useful engineering question is whether the executed request can differ from the reviewed one.
What a reviewer needs to see
| Field | Why it matters |
|---|---|
| Environment and target account | Prevent reviewing a test action that dispatches elsewhere |
| Exact resource and normalized request | Make the amount, recipient or file change explicit |
| Action and adapter versions | Bind the decision to the definition being executed |
| Provider state and observation time | Distinguish a current constraint from an earlier observation |
| Expiry and impact | Bound review lifetime and show allowance consumption |
| Success condition | Explain which provider evidence will establish completion |
Anlyon's governed-effect previews store this information and a binding digest. The dispatcher recomputes the digest from the persisted effect. A mismatch refuses dispatch. Refreshing a preview creates a new binding. An old approval does not transfer.
Binding and freshness are different
A request can be unchanged while the world has changed. The GitHub file-update adapter sends the reviewed blob SHA, so a concurrent file change can be rejected atomically. The Stripe refund adapter's preview shows the refundable balance as of review. Read the per-adapter guarantees.
Dispatch also checks current policy, environment halt, requester revocation and remaining impact capacity. Approval is permission to attempt the reviewed operation under those checks.
Avoid turning oversight into a rubber stamp
Route clearly allowed low-impact work through deterministic policy, deny forbidden work, and escalate operations that need judgment. Keep the review payload concrete. Do not let the model invent reviewer identity, approve its own request, or replace a structured preview with persuasive prose.
Measure approval volume and decision latency in your own deployment. A shorter queue is useful only if the policy still covers the consequential operations. No escalation rule guarantees an attentive reviewer.
What the binding covers
The binding mechanism applies to governed effects. With a local approval wrapper, Anlyon records the decision and your process runs the function. An approval records the decision, and provider evidence establishes the outcome.
Evaluate with a supported test action · Tool-selection guide · Current beta limits
Frequently asked questions
How do I stop an approved tool call changing before it runs?
Persist the exact reviewed operation, bind the approval to it, and refuse dispatch if the request, target, version or expiry no longer matches. For Anlyon governed effects, previews bind those values and the dispatcher recomputes the binding before sending.
What does the approval digest cover?
The digest binds the reviewed request, target, versions, preconditions and expiry to dispatch. Anlyon recomputes it before sending and refuses on any difference.
