Resources · 67
AI agents: authorize an action and verify its effect
Bind human approval to a specific operation, limit its lifetime and account for effects already executed.
· 2 min
What this guide helps achieve
- Define the exact action
- Bind approval to parameters
- Prevent reuse
- Verify effects and recovery
Quick check
- Do executed parameters match approved ones?
- Are expired or replayed approvals rejected?
- Does stopping leave an external effect to reconcile?
Step-by-step method
- 01
Define the exact action
Describe the object, recipient, amount or content and external effects. Classify operations by risk and reversibility. Approval to draft a message does not include permission to send it.
Deliverable: operation register and limits.
- 02
Bind approval to parameters
Show the person the decisive parameters and approval scope. Verify identity and permissions in the service executing the operation. Material changes should require a new decision.
Deliverable: per-action authorization contract.
- 03
Prevent reuse
Set an expiration, operation identifier and repeat protection. Test an old approval, a changed target and concurrent execution in a test environment. Model-generated text must not grant itself a permission.
Deliverable: negative test results.
- 04
Verify effects and recovery
Reconcile the external service result with the displayed state. Check missing responses before retrying. Record completed effects and possible compensations: stopping an agent does not unsend a delivered email.
Deliverable: timeline and recovery procedure.
Reusable worksheet
Complete with your authorised observations. These fields are a working template, not observed results.
| Field | Information to record |
|---|---|
| Operation | Object, approved parameters and external effects |
| Approval | Identity, scope, expiration and identifier |
| Recovery | External state, compensation and owner |
Worked example
Illustrative situation
Fictional example: an agent proposes a discount for a test account, then changes the amount after approval.
Decision and expected evidence
The service rejects the outdated authorization. The team also tests repeats and checks interruption effects separately.
Distinguish the mechanisms
| Mechanism | Purpose | Check or limitation |
|---|---|---|
| Proposal review | Review a plan or draft | Does not establish permission for an external effect |
| Operation authorization | Approve specified parameters | Expires and does not cover a changed operation |
Management indicators
| Indicator | What it measures | First action |
|---|---|---|
| Expired approvals rejected | Reuse test results | Investigate every unexpected acceptance |
| Reconciled effects | Operations linked to confirmed external state | Resolve uncertainty before retrying |
Common pitfalls
- Approve without displaying the target
- Confuse stopping a process with reversing effects
Frequently asked questions
Does Stop undo every action?
It can interrupt further actions. Completed effects require verification and, where possible, a separate compensation.
Is general permission sufficient?
The service must still check identity, object and operation. Sensitive actions may require approval bound to parameters.
What happens after a timeout?
Treat the outcome as uncertain and check external state before retrying to avoid duplicate effects.
Official references
References consulted: . The method and worksheet propose checks to adapt to your context; they do not constitute certification.






