Spurlock Studios
Contact
Share LinkedIn X
Two clipped paper packets. Thesis: HUMAN LOOP APPROVALS BECOME BOTTLENECKS.

Autonomy is a privilege you grant after a path proves it will not light money or reputation on fire. Human-in-the-loop (HITL) is that grant: the workflow prepares the action, a person authorizes it, then the graph continues.

Done wrong, HITL is a Slack graveyard — walls of JSON, no clock, no owner, buttons that open five tabs. Done right, it is one click with the consequence, the record, the risk cues, and a published SLA. n8n already ships the pause: Wait offloads the run and resumes on $execution.resumeUrl, and Slack’s Send and Wait for Response can keep the click inside the message.

This spoke is the authority layer of the Production n8n handbook. Across 500+ automations, the queues people actually click look like decisions. The queues they mute look like homework.

The short answer

  • Gate the irreversible class. Money, customer contact, and deletes stay behind a human until a written policy says otherwise.
  • One click, full context. What happens, why the system proposes it, a deep link to the record, risk cues, Approve / Reject, and a clock.
  • SLA + backup, not vibes. Pending past the clock escalates. Still pending holds or rejects. It never silent-sends.
  • Tokens are credentials. Signed, expiring, one-time, bound to approvalId + decision. Log who clicked.
  • Promote per class. Shadow the decision, measure disagreement, then remove the click for that class only.

What should require a human?

Default-gate anything that spends money, talks to a customer, or cannot be undone. n8n’s own human-in-the-loop for tools list is the same three: purchases, external communications, deletes. That is not a vibe. It is blast radius.

NIST’s AI RMF asks you to define and document human oversight (MAP 3.5). The human-AI appendix is explicit: some systems need a person in the decision, some do not. Your job is to write which is which, not to put a human on every CRM tag.

Action classDefaultWhyFirst thirty days of real traffic
Refund, payout, ad-spend change, vendor payGateCash leavesHuman on every item
Invoice / bill send (customer-visible)GateReputation + collectionsDraft auto; send gated
Email, SMS, public reply from a modelGateYou cannot unsay itEditor, not a rubber stamp
Delete, purge, irreversible permission changeGateRestore is a projectDual control if blast is wide
Legal / compliance-adjacent sendGateThe inbox is evidenceNamed role, logged actor
First publish of model-generated marketingGateBrand is a one-way doorEdit-then-approve
Internal draft, reverse-easy CRM fieldAuto OKLow blast, high volumeMonitor; no click
Enrichment that never contacts a humanAuto OKWrong field is an editSchema + replay
Team-only routing notificationAuto OKStill keep quality or they mute youDigest if volume spikes

Checklist — write this on the workflow, not in someone’s head:

  • Money movement named and gated
  • Customer-visible contact named and gated
  • Deletes / permission drops named and gated
  • Everything else listed as auto, with an owner who can demote it
  • “Unsure” defaults to a gate for the first cohort of live traffic

Removing a gate is a one-line policy change. Explaining an accidental customer email is a week.

What is a one-click approval versus a Slack graveyard?

A Slack graveyard is a channel that accumulates asks nobody can decide from the message. The tell is research: five tabs, a missing total, a JSON blob, no SLA, and a founder who is the only person who “knows the context.”

A one-click approval is a decision surface. Slack’s button element exists for this: primary for the affirmative, danger for the destructive, one of each in a set. n8n’s Approvals in Slack docs draw the same line — in-message click versus a link that opens a browser page.

SurfaceOne-clickGraveyard
First line“Refund $240 to Acme — card error, order 1842”“New item in approvals”
ButtonsApprove / Reject at the topBuried under a dump, or “see thread”
ContextAmount, customer, why, deep linkRaw node JSON
ActorNamed role or on-call@channel, or always the founder
ClockSLA on the card, escalate afterNone. Shame is the scheduler
After clickButtons removed, outcome writtenButtons stay; second click is folklore
FailureHold or rejectSilent send when someone is on a plane

Graveyard test — if any box is true, redesign the card before you add volume:

  • Approver must open another system to learn the dollar amount
  • Reject has no reason list, so people type novels or skip
  • The same human is the only path at 11pm and on Tuesday at 10am
  • Items older than the SLA have no backup and no safe default
  • The channel also carries memes, deploys, and “quick questions”

If the approver must open five tabs to understand the ask, you designed a research project.

What context must sit on the card?

Every approval item needs six fields. Miss one and people bounce to DMs, which is how you lose the audit trail.

FieldWhat it answersBad substitute
ConsequenceWhat happens if they approve, in plain languageNode name (HTTP Request3)
Why proposedScore, rule, or model summary“AI said so”
RecordDeep link to CRM / draft invoice / ticket / assetA pasted ID with no URL
Risk cuesAmount, new customer, unusual country, first-time SKUA feeling in the Slack emoji
ActionsApprove / Reject; optional Edit then approve“Thoughts?”
ClockSLA + who gets the escalate“when you can”

Procedure — build the payload before you build the Slack blocks:

  1. Write the consequence sentence a person would say out loud.
  2. Attach the system-of-record URL, not a screenshot.
  3. Add two risk cues that would change the decision (amount, newness, country, first send).
  4. Put Approve / Reject first in the actions block. Context sits under the buttons, not above a fold of JSON.
  5. Stamp slaDueAt and escalationRole on the approval row.
  6. Prefill reject reasons: spam, bad fit, needs edit, legal, wrong amount, duplicate.

Mobile rule: amount and customer name must be readable on a phone without landscape. People defer desktop-only UIs. Deferred approvals become bottlenecks, then someone demands full autonomy for the wrong class.

How do you pause an n8n workflow for a decision?

n8n pauses mid-execution. The Wait node offloads the run to the database and resumes when the condition hits. For approvals, that condition is On Webhook Call (or On Form Submitted if the editor lives in an n8n form). The resume URL is generated at runtime as $execution.resumeUrl — unique per execution, not a URL you pre-compute and cache.

Resume modeUse whenDo not use when
Wait → On Webhook CallEmail or a custom UI posts approve / rejectYou need Slack to identify the person (use Slack wait)
Slack Send and Wait for ResponseApprover lives in Slack and should not leave the appInstance is localhost; Slack cannot call you back
Wait → On Form SubmittedEditor must tweak a draft in a formThe decision is binary and the approver is on a phone in a warehouse
Queue table + status changeYou need a durable audit row finance already lives inYou were avoiding a table and hoped Slack history was the ledger

n8n Slack approvals have a real contract. Your instance must be reachable over public HTTPS. Interactivity Request URL is https://<instance>/webhook-waiting-slack (or your N8N_ENDPOINT_WEBHOOK_WAIT path). The Slack credential needs the app Signing Secret. Without it, buttons render and clicks do nothing — the workflow keeps waiting. One Slack app serves one n8n instance because Slack allows one Request URL per app.

Procedure — Wait + webhook (email or custom UI):

  1. Create the business payload and an approvalId.
  2. Write the approval row (Airtable, Postgres, or the system finance already opens).
  3. Send the message with two links or buttons that hit $execution.resumeUrl plus a bound decision.
  4. Set Limit Wait Time on the Wait node to the SLA, not to “forever.”
  5. On resume: verify token, write the actor, then continue or stop.
  6. On timeout: escalate once, then apply the safe default (hold or reject).

Do not bind a second irreversible write to the same click without an idempotency key on the side effect. Double-clicks happen. The second click must be a no-op.

Pick the surface the approver already lives in. Then pick the security model that surface can actually enforce.

n8n documents the split in Approvals in Slack: link buttons open an n8n page; anyone with the link can act; output is approved + respondedAt. In-Slack approvals stay in the message; n8n verifies the callback with Slack request signing; you can restrict who may click; output includes responder id, name, username, email, channel, and message id.

PatternActor identityAudit trailBest for
Slack in-message approve (Capture Who Responded on)Slack user, verified callbackStrong if you persist the outputOps that already live in Slack
Slack / email link to $execution.resumeUrlWhoever has the signed URLWeak on who unless you add authLow-sensitivity, short SLA, tiny team
Queue table + UI or Grid viewLogged-in roleStrongest for financeInvoices, refunds, dual control
n8n form waitThe person who submitted the formGood for edit-then-approveCopy, weird invoices, “fix the line”
Agent tool HITL (n8n tool review)Reviewer on the configured channelShows $tool.name + $tool.parametersModel-proposed writes: send, modify, delete

Slack interactivity posts a block_actions payload to your Request URL. Acknowledge fast. Do not hide the decision behind a modal unless the action is dual-control cash.

Checklist — choose one primary surface per queue:

  • Approvers named (role, not hero)
  • Sensitive items go to a private channel or DM, not #general
  • Restrict Who Can Approve is filled, or you have accepted that an empty list means anyone who can see the message
  • After Decision is Show Outcome and Remove Buttons so the card cannot be re-clicked as folklore
  • Finance-grade items also write a table row, even if Slack is the click

If you leave the approver list empty, n8n says every member of that channel can decide. That is a policy, not a default you sleepwalk into.

How do you publish an SLA and escalate?

A queue without a clock is a guilt system. People clear what they remember. The rest rot. Then someone “fixes” latency by removing the gate on the wrong class.

Write the SLA on the card and in the handbook. Match it to blast radius, not to how impatient the requester is.

ClassTarget time-to-decisionEscalate toSafe default if still pending
Customer-facing refund / failed chargeMinutes to a few hoursOn-call support leadHold — do not auto-refund
Invoice send ≤ written thresholdSame business dayFinance backupHold in draft
Invoice send / payout above thresholdSame day + dual if requiredFinance leadHold
Model-generated customer emailHours, not daysEditor backupReject / do not send
Internal content draftSame dayEditor backupHold; do not publish
Batch / back-office classifyNext business dayQueue ownerHold

Use the Wait node’s Limit Wait Time as the first clock. That is a resume condition, not a send. On timeout:

  1. Notify the backup with the same card, plus escalatedFrom and minutesPending.
  2. Start a second, shorter clock.
  3. If still pending, apply the safe default. For money and contact, that default is hold or reject.
  4. Write timedOut: true on the approval row so the metric is visible.

Never encode “if nobody clicks, send it.” That is silent autonomy with extra steps. The EU AI Act Article 14 language on high-risk systems is the same idea in legal clothes: a person must be able to override, disregard, or interrupt. A timeout that sends is the opposite of interrupt.

Batch the low-risk class into two daily digests if true urgency is low. Keep real-time for customer-facing cash and contact. Mixing both in one channel is how the digest trains people to ignore the refund.

How do you treat approval tokens as credentials?

Decision links are credentials. An open “approve” URL that never expires is how invoices send themselves after a forward.

n8n’s Wait resume URL is unique per execution and, in current versions, carries a signature so callers cannot guess /webhook-waiting/<id>. Still treat it as a secret. Slack in-message approvals are stronger on identity because n8n verifies Slack’s request signing and can restrict the actor. If you roll your own webhook, n8n’s Webhook credentials give you Basic, Header, or JWT — “None” is for local tests.

GitHub’s validating webhook deliveries write-up is the pattern to copy when you are not using Slack’s signer: HMAC over the raw body, compare in constant time, reject on mismatch.

ControlWhyFailure if skipped
Expiry (hours, not weeks)Forwards and screenshots age outLast month’s link still sends
Bind token to approvalId + decisionCannot reuse an approve token as a reject on another rowConfused deputy
One-time useSecond click is a no-opDouble send
No PII in the query stringLogs, proxies, and referrers keep URLsCustomer email in CloudFlare logs
Actor from a trusted surfaceSlack user id, SSO user, not “someone clicked”Audit says “unknown”
Signed callback (Slack secret or HMAC)Proves the POST is not a strangerAnyone who found the URL decides

Checklist — security review before the first live refund:

  • Resume URL is $execution.resumeUrl at runtime, never a cached string
  • Slack Signature Secret is on the credential if you use in-message buttons
  • Custom webhook has Header or JWT auth, not open
  • Approval row stores decidedBy, decidedAt, source (slack / email / ui)
  • PII stays in the POST body or the Slack payload, not ?email=
  • Expired or replayed tokens write a security event, not a send

If you cannot name who approved, you do not have an approval. You have a coin flip with a button.

When do thresholds and dual control belong?

Thresholds shrink volume without removing control where it hurts. Dual control is for the class where one mistake is existential. Most SMB graphs need the first. Few need the second. Pretending every invoice is dual control is how you recreate the graveyard.

PatternRuleExample
Auto under, human overWritten dollar or cohort lineInvoice send ≤ $X after probation; human above
Known-customer autoAllowlist + clean historyRepeat SKU, same legal entity, no country change
First-time always humanNew customer, new bank, new countryFirst payout, first public reply template
Dual controlTwo distinct humansWire, bulk delete, production permission drop
Maker / checkerThe person who built the payload cannot approve itFounder-built refund still needs finance

Stripe’s invoice lifecycle is the money example. A new invoice starts as a draft. If you leave automatic advancement on (auto_advance=true), Stripe can finalize, email, and retry collection without your gate. For a human-gated send, set auto_advance=false, keep the object in draft, and only finalize + send after the click. The threshold applies to send, not to draft create.

Procedure — write the line so a substitute can apply it:

  1. Name the class (invoice send, refund, ad spend, delete).
  2. Write the auto line in dollars or in cohort language, with a date and an owner.
  3. Write the dual-control line, or write “none.”
  4. Put both numbers on the approval card so the clicker sees the policy.
  5. Revisit the line from metrics, not from a loud week.

Do not hide the threshold in a Code node comment. The next operator will not find it at 2am.

How do you design edit-then-approve?

Binary Approve / Reject is fine for a refund under a written line. Content, weird invoices, and model-proposed emails need an edit path. If approve freezes the first draft forever, editors bypass you and paste into the tool by hand. You lose the trail. They keep the speed.

n8n’s tool-level HITL shows the reviewer $tool.name and $tool.parameters before the write. That is the right instinct for agents. For content and invoices, store the draft in the system the editor already uses, and make Approve read the current draft.

StepOwnerRule
1. Write draftGraphSystem of record, not a Slack snippet
2. Open approvalGraphCard points at the live draft URL
3. EditHumanChange the draft in place
4. ApproveHumanGraph re-reads the draft, then sends / publishes
5. Request changesHumanReturns to generator or rewriter with a reason code
6. RejectHumanStops. Reason becomes an intake ticket

Checklist — edit-then-approve that people will use:

  • Approve does not hash the original model output as the payload
  • “Request changes” is a first-class button, not a DM
  • Reject reasons are prefilled
  • “Approve with note” is optional and short — no novel required
  • The sent object id is written back to the approval row

Lead routing is the opposite shape. Humans should rarely approve each lead. They should approve rule changes. Day-to-day assignment can be automatic if the rules are written. Gating every inbound lead is how you invent a ticket desk in Slack.

Who is allowed to click?

Ambiguity creates either a founder bottleneck or an intern with a wire. Publish an authority matrix next to the workflows. NIST’s appendix on human-AI configurations is the same demand: define who operates, who interacts, and who oversees.

ActionAutoRole ARole B (dual)
Lead assignYes, after rules signed——
CRM tag / source writeYes——
Invoice send ≤ $XAfter probationFinance ops—
Invoice send > $XNoFinance opsFinance lead
RefundNoSupport leadFinance if over line
Customer email from a modelNoEditor—
Bulk delete / permission dropNoOwnerSecond owner
Ad spend changeNoMedia leadFinance if over line

n8n will enforce a Slack allowlist if you fill Restrict Who Can Approve. It will not invent your matrix. An empty list is “anyone who can see the message.” Post cash approvals to a private channel or a DM.

Checklist — role design that survives vacation:

  • Every gated class has a primary and a backup
  • Founder is not the primary on routine refunds
  • Dual-control roles are two people, not one person with two Slack accounts
  • Offboarding removes the person from the Slack allowlist and the table ACL the same day
  • The matrix lives where the next operator will look (handbook + the workflow sticky note)

Route to roles, not heroes. On-call rotation beats “always ping William.”

How do you keep volume inside attention?

HITL fails when volume exceeds attention. The fix is shaping, not “try harder” and not “remove the alerts.”

LeverWhen it helpsWhen it lies
Raise auto-threshold for a proven classReject rate is low and understoodYou raise it to hide a UX problem
Two daily digestsLow-risk, no customer waitingYou digest refunds
Split queues (finance vs content)Specialists decide fasterYou split and then @channel both
Surge staffing on launch weekYou know the spike is temporaryYou hire nobody and “hope”
Shed optional automations in peak seasonAttention is finiteYou shed the error handler instead
Shadow mode before autoYou want evidenceYou skip it because the demo is Friday

Workload checklist:

  • Each queue has a weekly volume cap the role agreed to
  • Overflow has a written shed (digest, raise threshold, pause a non-critical graph)
  • Pager / approval channel is not the same place as social chat
  • Duplicate cards collapse — one approval row per approvalId
  • You measure bypass rate (DMs, “just send it”) as a first-class metric

Do not “fix” overload by removing alerts. That recreates silent autonomy. Do not “fix” it by adding a second Slack channel that repeats the first. That recreates the graveyard with a new name.

Which metrics tell you to promote or demote?

Promote and demote from a table, not from a loud anecdote. Review monthly with the queue owners.

MetricHealthy signalUnhealthy signalMove
Median time-to-decisionInside the published SLAGrowing week over weekShape volume or add backup
Reject rateStable, reasons understoodSpike with no rule changePause promotions; fix intake
Edit rate (content)Falling as drafts improveStuck highThe extract is wrong, not the editor
Escalation rateRareBackup always decidesPrimary is a fiction
Timeout → safe-default rateNear zeroCommonSLA is fantasy or staffing is
Bypass rate (DMs, shadow process)Near zeroRisingUX is homework; they left
Disagreement in shadow modeLow on that classHighDo not remove the click

Autonomy promotion — all boxes, not “most”:

  • Volume is high enough that the gate costs real hours
  • Reject / edit rate is low and the reasons are boring
  • Failure blast radius is contained
  • Monitoring and the error path are proven
  • Owner agrees in writing (a Slack thread is enough if you keep it)

Demote immediately when a vendor changes behavior or a bad send escapes. Promotion is per class. “The invoice graph is trusted” is not permission to auto-send model email.

When should you skip HITL — and how do you promote later?

Skip the click when the action is easily reversible, low blast, and high volume. Tagging a CRM contact source=webinar does not need a human. It needs a schema, an owner, and a way to rewrite the field. HITL is scarce. Spend it where irreversible harm lives.

Skip HITLKeep HITL
Reverse-easy field writeMoney out
Internal notification to a team that asked for itCustomer-visible send
Idempotent upsert of enrichmentDelete / purge
Re-compute a score into a sandbox fieldPermission or legal change
Draft create in Stripe / Xero / QBOFinalize + send

Promotion path that does not surprise finance:

  1. Run shadow mode: the system decides, the human still clicks, you compare for a fixed window (two weeks is a common studio default — write yours).
  2. Measure disagreement rate on that class only.
  3. If disagreement is low and reasons are understood, remove the click for that class.
  4. Keep the card template. You will need it the week a vendor ships a breaking change.
  5. Tell the owner in writing. A silent promotion is how you get a silent incident.

Shadow mode is cheaper than an incident. It is also how you earn trust from a skeptical finance partner who has been burned by a “helpful” bot.

What do reject storms actually mean?

A reject storm is a sensor. High rejects mean the machine is wrong, the intake changed, or the card is unreadable. They do not mean humans are “slowing innovation.”

Likely causeWhat you seeWhat you do
Bad upstream dataSame reject reason, many rowsFix the extract; do not nag the queue
Rule / price changeSpike on one SKU or one countryUpdate the rule; announce it
UXHigh bypass + “I didn’t understand”Redesign the card
Model drift (content / email)Edit rate up, tone complaintsPin the prompt and the model; re-sample
StaffingTime-to-decision up, reject rate flatEscalate path and volume levers
True policy catchRejects cluster on a new abuse patternKeep the gate; write the pattern down

Procedure when reject rate jumps:

  1. Pause autonomy promotions on that class.
  2. Sample twenty rejects. Tag each: data, rule, UX, model, policy.
  3. Fix the winning tag upstream.
  4. Only then talk about speed.

If you punish people for rejecting, they will approve to clear the queue. That is how you get a rubber stamp with a human face.

How do approvals differ from error workflows?

Approvals are intentional pauses. Error workflows are failure pauses. If you dump both into one Slack list, operators will treat refunds like stack traces and stack traces like homework.

n8n’s Error Trigger wakes a human when a linked execution dies. That alert needs severity, owner, execution link, failed node, and a next action — the contract in n8n error workflows operators actually read. An approval card needs consequence, record, risk, buttons, and a clock. Different job, different UI, different urgency.

Approval queueError / failure queue
Why it pausedPolicy: a human must authorizeThe graph died or a dependency blinked
Happy clickApprove / Reject / EditAck, assign, replay from DLQ
Safe default on timeoutHold or rejectPage the backup; do not “approve” the failure
Identity neededWho authorized the side effectWho is fixing it
Success lookDecision inside SLARepair inside severity SLA

Keep them in separate channels. An approval that lands in #alerts will be muted with the retries. An error that lands in #approvals will wait for a finance person who cannot replay a webhook.

What belongs in the handoff packet?

Client-delivered graphs die when the only approver leaves and nobody knows the threshold. Put the packet in the repo and in the client’s ops doc the week you ship.

Packet itemWhy it exists
Gated action listMoney / contact / deletes, plus any extras you added
Authority matrixWho clicks, who is backup, who is dual
Thresholds + last review dateThe dollar lines, not “use judgment”
Where decisions are loggedTable name, Slack channel, retention
Token / Slack app notesRequest URL, signing secret owner, expiry
How to pause in two minutesDisable the workflow or flip approvalsRequired=true
How to change a thresholdWho writes it, who reviews it
Shadow-mode historyLast promotion, disagreement rate

Offboarding checklist:

  • Remove the person from Restrict Who Can Approve
  • Remove table ACL / SSO group
  • Confirm the backup can clear a live item on a phone
  • Rotate any personal resume-link bookmarks (they should not exist)
  • Re-send the packet to the remaining owner

Studios that skip this get the emergency Slack call six months later. The graph still works. The company cannot decide.

FAQ

What is human-in-the-loop automation?

A design where irreversible or high-risk steps pause for a person to approve, reject, or edit before the workflow continues. The automation prepares the payload and the context. The human authorizes the side effect. It is not a personality setting on a model, and it is not a forever-click on every CRM write.

How do I build an approval workflow in n8n?

Create the business payload, write an approval record, and pause with Wait-on-webhook or Slack Send and Wait for Response. Resume on the decision, log the actor, then continue or stop. Bind an idempotency key on the write, set Limit Wait Time to the SLA, and escalate stale items to a named backup instead of silent-sending.

Will approvals slow the business down?

Only if you gate the wrong things or make the decision hard. Gate money, customer contact, and deletes. Put the consequence and the buttons on one card. Publish an SLA with a backup. Auto-promote a narrow class after shadow mode and a boring reject rate. Slow is five tabs and no owner, not one click with a clock.

Should AI decisions auto-run?

Not for money, customer contact, or deletes until that class has measured disagreement in shadow mode. Let the model propose. Let a human dispose. n8n can pause an agent tool call and show the reviewer the tool name and parameters — use that for sends, modifies, and deletes, and promote per tool, not globally.

What is a good approval SLA?

Match blast radius. Customer-facing refunds: minutes to a few hours. Invoice sends and model emails: same business day. Internal drafts and batch classify: next business day. Publish the number on the card. Timeout escalates, then holds or rejects. A timeout that sends is silent autonomy.

How do approvals interact with dead-letter queues?

They do not share a list. Approvals are policy pauses with Approve / Reject. Dead-letter and error-workflow items are failure pauses with replay. Mix them and operators mute both. Give each queue its own channel, owner, and urgency. Wire failures through an Error Trigger handler people will actually read, not through the finance approval card.

CTA

Control without throughput is theater. Throughput without control is next quarter’s incident report.

Design gates people will click. Read the handbook, then use the automation lane or book the audit to install one-click HITL with a clock.

FAQ

What questions does this article answer?

What is human-in-the-loop automation?
A design where irreversible or high-risk steps pause for a person to approve, reject, or edit before the workflow continues. The automation prepares the payload and the context. The human authorizes the side effect. It is not a personality setting on a model, and it is not a forever-click on every CRM write.
How do I build an approval workflow in n8n?
Create the business payload, write an approval record, and pause with Wait-on-webhook or Slack **Send and Wait for Response**. Resume on the decision, log the actor, then continue or stop. Bind an idempotency key on the write, set Limit Wait Time to the SLA, and escalate stale items to a named backup instead of silent-sending.
Will approvals slow the business down?
Only if you gate the wrong things or make the decision hard. Gate money, customer contact, and deletes. Put the consequence and the buttons on one card. Publish an SLA with a backup. Auto-promote a narrow class after shadow mode and a boring reject rate. Slow is five tabs and no owner, not one click with a clock.
Should AI decisions auto-run?
Not for money, customer contact, or deletes until that class has measured disagreement in shadow mode. Let the model propose. Let a human dispose. n8n can pause an agent tool call and show the reviewer the tool name and parameters — use that for sends, modifies, and deletes, and promote per tool, not globally.
What is a good approval SLA?
Match blast radius. Customer-facing refunds: minutes to a few hours. Invoice sends and model emails: same business day. Internal drafts and batch classify: next business day. Publish the number on the card. Timeout escalates, then holds or rejects. A timeout that sends is silent autonomy.
How do approvals interact with dead-letter queues?
They do not share a list. Approvals are policy pauses with Approve / Reject. Dead-letter and error-workflow items are failure pauses with replay. Mix them and operators mute both. Give each queue its own channel, owner, and urgency. Wire failures through an Error Trigger handler people will actually read, not through the finance approval card.
Sources

Last reviewed

More from this lane

Automation

All →
Book the audit