Resources · 67

AI agents: authorize an action and verify its effect

Bind human approval to a specific operation, limit its lifetime and account for effects already executed.

· 2 min

Laptop displaying code on a desk Illustration · fictional scene

What this guide helps achieve

  • Define the exact action
  • Bind approval to parameters
  • Prevent reuse
  • Verify effects and recovery

Quick check

  • Do executed parameters match approved ones?
  • Are expired or replayed approvals rejected?
  • Does stopping leave an external effect to reconcile?

Step-by-step method

  1. 01

    Define the exact action

    Describe the object, recipient, amount or content and external effects. Classify operations by risk and reversibility. Approval to draft a message does not include permission to send it.

    Deliverable: operation register and limits.

  2. 02

    Bind approval to parameters

    Show the person the decisive parameters and approval scope. Verify identity and permissions in the service executing the operation. Material changes should require a new decision.

    Deliverable: per-action authorization contract.

  3. 03

    Prevent reuse

    Set an expiration, operation identifier and repeat protection. Test an old approval, a changed target and concurrent execution in a test environment. Model-generated text must not grant itself a permission.

    Deliverable: negative test results.

  4. 04

    Verify effects and recovery

    Reconcile the external service result with the displayed state. Check missing responses before retrying. Record completed effects and possible compensations: stopping an agent does not unsend a delivered email.

    Deliverable: timeline and recovery procedure.

Reusable worksheet

Complete with your authorised observations. These fields are a working template, not observed results.

FieldInformation to record
OperationObject, approved parameters and external effects
ApprovalIdentity, scope, expiration and identifier
RecoveryExternal state, compensation and owner

Worked example

Illustrative situation

Fictional example: an agent proposes a discount for a test account, then changes the amount after approval.

Decision and expected evidence

The service rejects the outdated authorization. The team also tests repeats and checks interruption effects separately.

Distinguish the mechanisms

MechanismPurposeCheck or limitation
Proposal reviewReview a plan or draftDoes not establish permission for an external effect
Operation authorizationApprove specified parametersExpires and does not cover a changed operation

Management indicators

IndicatorWhat it measuresFirst action
Expired approvals rejectedReuse test resultsInvestigate every unexpected acceptance
Reconciled effectsOperations linked to confirmed external stateResolve uncertainty before retrying

Common pitfalls

  • Approve without displaying the target
  • Confuse stopping a process with reversing effects

Frequently asked questions

Does Stop undo every action?

It can interrupt further actions. Completed effects require verification and, where possible, a separate compensation.

Is general permission sufficient?

The service must still check identity, object and operation. Sensitive actions may require approval bound to parameters.

What happens after a timeout?

Treat the outcome as uncertain and check external state before retrying to avoid duplicate effects.

Official references

References consulted: . The method and worksheet propose checks to adapt to your context; they do not constitute certification.