Human approval in agent workflows: a design checklist

VTech Studio monogram

VTech Studio

Two VTech Studio members discussing work at the studio

A practical checklist for designing agent actions that people can understand, review and control before consequential changes are executed.

An approval button is useful when it helps someone understand the action they are authorizing. If the person cannot see the destination, the data involved or the expected effect, the button adds friction without providing meaningful control.

This checklist describes design goals for agent workflows. It is not a claim that VTech Studio’s developing workspace already implements every control below.

Show the concrete action

Explain what will happen in specific terms: create a task, publish a page, update a record or send a message. Show the destination and the exact content when those details affect the decision. Avoid a generic “continue” prompt that hides the consequence.

Put review near execution

Prepare the work before asking someone to approve it. A draft message or a visible change is easier to assess than an intention. If the destination or scope changes after approval, the product should make that change clear and obtain a new decision where appropriate.

Distinguish reading from changing

Finding a document and modifying it are different operations. Grouping both behind a broad access switch can confuse users. Design separate controls for context access and actions that change external systems.

Use the narrowest capability that can complete the task. A workflow that needs a document summary may not need permission to delete or share the document.

Preserve the reason and the result

An action record should connect the user’s request, the reviewed proposal and the outcome. If a tool fails, the interface should say what completed and what remains unresolved. A failed request should not appear as a successful change.

Account for untrusted input

Documents and tool results can contain instructions that conflict with the user’s goal. They should be treated as data, not as permission to run new actions. MCP security guidance highlights risks around local server setup and execution privileges; approval and clear capability boundaries belong in the surrounding application.

Start with one workflow

For our Agent Collaboration Workspace, we are exploring shared context and agent coordination with humans in control. A concrete workflow, such as reviewing a research handoff before publishing it to a team, provides a useful way to test whether the controls are understandable.

Reference: MCP security best practices.