Skip to content

Automation · System design

Designing the approval step: human-in-the-loop automation people actually use

“A human will review it” is not a design. How to decide what needs approval, and how to build approval steps that are fast enough not to be bypassed.

By MDSPreview edition2 min read

This is a preview edition under review. It may change before publication.

Almost every automation proposal includes the reassuring line “a human will review it”. Few specify who, when, with what information, or what happens if nobody does. The result is predictable: either the review becomes a rubber stamp, or it becomes a bottleneck that people quietly route around.

Decide what actually needs approval

Approval is expensive. It interrupts someone, adds delay and creates a queue. Reserve it for steps where a mistake is costly or hard to reverse:

  • Money moving: payments, refunds and postings above a defined threshold.
  • Commitments made to customers: prices, deadlines, contract terms.
  • Decisions about people: hiring, credit, access, eligibility.
  • Cases the system is unsure about — low confidence, or inputs unlike anything it has seen.

Everything else should run automatically, with logging good enough to review after the fact. Approving low-risk steps does not make a system safer; it trains people to click “approve” without reading.

Make the decision easy to make well

An approval request should contain everything needed to decide, in the place the approver already works. A good request shows:

  1. What the system intends to do, in one sentence.
  2. Why — the inputs and the reasoning, including anything unusual.
  3. What happens on approve, reject, and edit.
  4. When it will escalate if nobody responds.

Rule of thumb

If approving a request requires opening three other systems to check it, the approval step will be bypassed within a month.

Design for silence

The most common failure is not a wrong decision but no decision. Every approval step needs a timeout and a defined behaviour: escalate to a deputy, fall back to a safe default, or pause and alert. Choose deliberately, because “wait forever” is also a choice — usually the wrong one.

Close the loop

Approvals generate the most valuable data an automation has: cases where a person disagreed with the system. Record every rejection and edit with a short reason. Reviewed regularly, they show where rules need adjusting, where the AI step needs better instructions, and where approval could safely be removed.

Done well, human-in-the-loop is not a safety blanket thrown over an automation. It is a designed part of the system, with its own measures: response time, agreement rate, and how often it catches something that matters.

Working through a decision like this?

We are happy to look at your specific situation and tell you what we would do.