ContourIQ
AI workflow control guide

Put human approval where consequences begin.

A practical framework for deciding what AI may observe, prepare, execute within bounds, or pause for a named person—before a workflow reaches customers, money, commitments, or sensitive systems.

Published September 8, 20269-minute guideWritten by ContourIQ
Start with authority

Human-in-the-loop is not one setting.

An AI workflow can have different authority at each step. The useful question is not whether AI is autonomous; it is which specific action is allowed, under which conditions, with what evidence, and who owns the exception.

AUTHORITY 01Usually automatic

Observe

Read permitted information, detect an event, classify a request, or prepare an internal summary without changing a business record or contacting someone.

  • Identify a new inquiry
  • Summarize an inbox thread
  • Flag a missing field
AUTHORITY 02Draft for review when consequences matter

Prepare

Recommend a route, draft a response, assemble a document, or propose a record update while a person remains responsible for the consequential action.

  • Draft a customer reply
  • Prepare a proposal
  • Recommend lead routing
AUTHORITY 03Automatic only inside explicit rules

Act within bounds

Complete a reversible, tested action when required data, permissions, thresholds, consent, and stop conditions are satisfied.

  • Create an internal task
  • Send an approved reminder
  • Update an allowed CRM field
AUTHORITY 04Named human decision

Approve or escalate

Pause before sensitive, unusual, expensive, public, legally meaningful, money-touching, access-changing, or hard-to-reverse actions.

  • Approve pricing or terms
  • Authorize a refund
  • Publish a sensitive response
Illustrative approval matrix

Define posture, owner, evidence, and stop condition.

Use this as a workshop starting point. The final matrix should be specific to your workflow, permissions, systems, customers, and risk decisions.

Illustrative human approval matrix for common AI workflow actions
ActionDefault postureAccountable roleEvidence to retainStop or escalate when
Internal task creationMay run automaticallyProcess owner defines rulesTrigger, assignee, due date, source recordMissing owner, duplicate task, or invalid record
Routine appointment reminderMay run within approved template and consent rulesService or operations ownerRecipient, approved template, send status, opt-out stateOpt-out, disputed appointment, sensitive note, or delivery failure
Customer-service responseDraft first; bounded routine replies may earn automationService owner or assigned representativeRequest, approved source, draft, edits, final senderComplaint, uncertainty, sensitive data, exception, or high-value account
Lead qualification and routingRecommend or route inside documented criteriaSales owner defines criteria and exceptionsSource, stated needs, rule or reason, assigned ownerAmbiguous intent, conflicting data, restricted category, or no owner
Proposal pricing or scopeHuman approval before commitmentAuthorized sales or delivery ownerInputs, price source, scope version, approver, timestampMissing inputs, nonstandard discount, unusual terms, or stale pricing
Contract, refund, or payment actionExplicit approvalAuthorized business roleSource record, amount or terms, approver, decision, resulting actionAny mismatch, permission failure, threshold breach, or disputed request
Public content or reputation responseReview before publishing when brand or sensitivity is involvedNamed communications or business ownerSource context, draft, edits, channel, publisherLegal threat, crisis, personal data, uncertain facts, or hostile context
Access, deletion, or security changeAuthorized human approval; consider separation of dutiesSystem or security ownerRequester, target, reason, approver, execution resultUnverified request, excessive scope, missing backup, or failed authorization
Approval design patterns

Use the smallest control that fits the consequence.

Blanket approval creates unnecessary queues. Blanket autonomy hides consequential decisions. These patterns let one workflow use different controls at different steps.

PATTERN 01

Threshold approval

Allow routine values inside an approved range and pause when an amount, discount, risk, or scope crosses the threshold.

PATTERN 02

Field-level approval

Let the workflow update low-risk fields while protecting pricing, permissions, commitments, status, or other consequential fields.

PATTERN 03

Exception routing

Define named reasons to stop and route: missing information, conflicting records, unusual language, delivery failure, or an unsupported request.

PATTERN 04

Preview and edit

Show the source context, proposed action, and editable output together so the approver can make an informed decision.

PATTERN 05

Timeout and fallback

Specify what happens when no one responds: remind, reassign, expire, or return to manual handling instead of silently proceeding.

PATTERN 06

Pause and revoke

Give an accountable owner a documented way to pause the workflow and revoke credentials or permissions when behavior is questionable.

Implementation sequence

Earn authority one action at a time.

Start conservative, test the actual failure modes, and expand only when observed behavior supports a wider boundary. A successful demo is not the same as an operated workflow.

  1. 01

    Map the action

    Name the trigger, information used, proposed action, affected person or system, and what changes if the action succeeds.

  2. 02

    Classify consequence

    Consider reversibility, money, commitments, privacy, security, public impact, customer harm, and the cost of delay.

  3. 03

    Assign authority

    Choose automatic, prepare-only, approval-required, or prohibited—and name who owns approval and exceptions.

  4. 04

    Test the boundaries

    Exercise normal, incomplete, conflicting, adversarial, high-value, and failure cases before widening authority.

  5. 05

    Launch narrowly

    Begin with limited scope, visible activity, conservative permissions, and a practical return to manual handling.

  6. 06

    Review real behavior

    Measure overrides, errors, escalations, response time, completion, and outcomes before changing the approval posture.

Common questions

Human control is a workflow design decision.

Can an AI workflow take action without human approval?

It can for explicitly permitted, low-risk, tested actions within clear rules and system permissions. Human approval is a stronger default when an action is sensitive, unusual, expensive, public, money-touching, access-changing, or difficult to reverse.

Does human approval make automation too slow?

Poorly designed approval can create a bottleneck. The answer is not to remove every control; it is to reserve approval for consequential decisions, give approvers useful context, route to a named role, define timeouts, and automate reversible steps around the decision.

Who should approve an AI-generated action?

The role already accountable for that business decision should usually approve it. Approval should follow authority, not technical familiarity: pricing may belong to sales leadership, refunds to an authorized service role, and access changes to a system owner.

Is a human-in-the-loop enough to make an AI workflow safe?

No. Approval is one control. The workflow also needs appropriate data access, approved sources, permissions, tests, stop conditions, exception handling, monitoring, documentation, and a defined response when connected systems fail.

What should an approval record contain?

The useful record depends on the systems and risk, but it may include the trigger, source context, proposed action, model or rule output, edits, decision, approver, timestamp, execution result, and escalation reason. Logging capability must be confirmed for the actual tools.

Free AI workflow audit

Map the authority before connecting the action.

Bring one AI-assisted process. We'll identify its sources, proposed actions, approval boundaries, exceptions, and accountable owners before deciding what is worth implementing.

Audit an AI workflow