---
title: "AI agent sends: who approves the message and recipient."
description: "Assign an approver for each agent send. Preview the account, recipient, text, and attachments, then bind approval to the exact action and verify it."
canonical: "https://scalewithsearch.com/articles/who-approves-what-an-ai-agent-sends"
date: "2026-08-17"
modified: "2026-09-19"
---
## Site navigation

- [Scale With Search](https://scalewithsearch.com/)
- Real estate
  - Real estate
    - [Real estate](https://scalewithsearch.com/for/real-estate)
- Work
  - Start here
    - [Send your brief](https://scalewithsearch.com/work#send-your-brief)
    - [Prepare your six-question brief](https://scalewithsearch.com/work#prepare-your-six-question-brief)
  - Build
    - [Site build, content library with SEO, signal desk](https://scalewithsearch.com/work)
- For your business
  - Trades and home services
    - [Auto body and collision shops](https://scalewithsearch.com/for/auto-body-and-collision-shops)
    - [Foundation and home repair contractors](https://scalewithsearch.com/for/foundation-and-home-repair)
    - [Garage door and fencing contractors](https://scalewithsearch.com/for/garage-door-and-fencing-contractors)
    - [HVAC contractors](https://scalewithsearch.com/for/hvac-contractors)
    - [Janitorial and commercial cleaning companies](https://scalewithsearch.com/for/janitorial-and-commercial-cleaning)
    - [Locksmiths](https://scalewithsearch.com/for/locksmiths)
    - [Moving companies](https://scalewithsearch.com/for/moving-companies)
    - [Pest control companies](https://scalewithsearch.com/for/pest-control-companies)
    - [Plumbing and electrical contractors](https://scalewithsearch.com/for/plumbing-and-electrical-contractors)
    - [Restoration and water or fire damage companies](https://scalewithsearch.com/for/restoration-and-water-fire-damage)
    - [Roofing companies](https://scalewithsearch.com/for/roofing-companies)
    - [Towing companies](https://scalewithsearch.com/for/towing-companies)
    - [Tree services and landscaping companies](https://scalewithsearch.com/for/tree-services-and-landscaping)
    - [Solar installers](https://scalewithsearch.com/for/solar-installation)
    - [General contractors](https://scalewithsearch.com/for/general-contractors-and-construction)
    - [Paving, concrete, and flooring contractors](https://scalewithsearch.com/for/paving)
  - Practices and professional services
    - [Bookkeeping and tax practices](https://scalewithsearch.com/for/bookkeeping-and-tax-practices)
    - [Dental practices](https://scalewithsearch.com/for/dental-practices)
    - [Family and criminal defense law firms](https://scalewithsearch.com/for/family-and-criminal-defense-law-firms)
    - [Med spas and aesthetics practices](https://scalewithsearch.com/for/med-spas-and-aesthetics)
    - [Personal injury law firms](https://scalewithsearch.com/for/personal-injury-law-firms)
    - [Veterinary clinics](https://scalewithsearch.com/for/veterinary-clinics)
    - [Gyms and fitness studios](https://scalewithsearch.com/for/fitness)
    - [Therapy and outpatient health practices](https://scalewithsearch.com/for/therapy-and-outpatient-health)
    - [Medical billing companies](https://scalewithsearch.com/for/medical-billing)
    - [Insurance agencies](https://scalewithsearch.com/for/insurance-agencies)
    - [Financial advisors](https://scalewithsearch.com/for/financial-advisors)
    - [Property management companies](https://scalewithsearch.com/for/property-management)
    - [Recruiting and staffing agencies](https://scalewithsearch.com/for/recruiting-and-staffing)
    - [Architects and interior designers](https://scalewithsearch.com/for/architects-and-interior-designers)
    - [Logistics and supply chain companies](https://scalewithsearch.com/for/logistics-and-supply-chain)
  - Agencies, MSPs, and manufacturing
    - [IT and managed service providers](https://scalewithsearch.com/for/it-and-managed-service-providers)
    - [Machine shops and precision manufacturers](https://scalewithsearch.com/for/machine-shops-and-precision-manufacturing)
    - [Marketing agencies and freelancers](https://scalewithsearch.com/for/marketing-agencies-and-freelancers)
    - [SEO agencies and consultants](https://scalewithsearch.com/for/seo-agencies-and-consultants)
    - [Small manufacturers and fabricators](https://scalewithsearch.com/for/small-manufacturers-and-fabricators)
  - Restaurants, shops, studios, and nonprofits
    - [Restaurants and hospitality businesses](https://scalewithsearch.com/for/restaurants-and-hospitality)
    - [Retail stores and ecommerce sellers](https://scalewithsearch.com/for/retail-and-ecommerce)
    - [Photographers, event planners, and travel agents](https://scalewithsearch.com/for/photographers)
    - [Churches and nonprofits](https://scalewithsearch.com/for/churches-and-nonprofits)
  - [All industries](https://scalewithsearch.com/for/)
- Learn
  - For your office
    - [Office job guides](https://scalewithsearch.com/guides/)
    - [Browser calculators](https://scalewithsearch.com/tools/)
  - Start here
    - [How it works](https://scalewithsearch.com/how-it-works)
    - [Free Starter Kit](https://scalewithsearch.com/kit/business-memory-starter-kit.zip)
    - [Synthetic specimen](https://scalewithsearch.com/specimen/working-session-specimen.zip)
  - Guides
    - [The Complete Guide to Business Memory for AI Agents](https://scalewithsearch.com/articles/business-memory-for-ai-agents-guide)
    - [The Complete Small-Business Guide to AI Agent Governance](https://scalewithsearch.com/articles/ai-agent-governance-guide-small-business)
    - [The Complete Guide to Leaving Vendor AI Memory](https://scalewithsearch.com/articles/leaving-vendor-ai-memory-guide)
  - Articles by cluster
    - [Business memory](https://scalewithsearch.com/articles/business-memory-for-ai-agents-guide)
    - [Agent governance](https://scalewithsearch.com/articles/ai-agent-governance-guide-small-business)
    - [Migration and ownership](https://scalewithsearch.com/articles/leaving-vendor-ai-memory-guide)
  - For machines
    - [llms.txt](https://scalewithsearch.com/llms.txt)
    - [llms-full.txt](https://scalewithsearch.com/llms-full.txt)
    - [Machine view](https://scalewithsearch.com/?view=machine)
- Company
  - Evidence
    - [Proof](https://scalewithsearch.com/proof)
  - Company
    - [About](https://scalewithsearch.com/about)

# Who Approves What an AI Agent Sends.

A sales [agent](/articles/what-is-an-ai-agent-in-a-small-business) drafts a clean follow-up. The recipient is wrong.

The contact shares a name with another account. The wording is harmless, but the message exposes a private project to the wrong company. A final "looks good" prompt would not have caught the destination.

External approval must cover the action, not only the prose.

The approver needs to see what will happen, where it will happen, under which account, and with what data. The system must stop until that decision is recorded.

## Approval belongs at the capability

The [small-business agent governance guide](/articles/ai-agent-governance-guide-small-business) places this send gate alongside source ownership, tests, change control, and incident handling.

Prompts can tell a model not to send. The enforceable boundary sits in the email, social, calendar, payment, deployment, or CRM tool.

OpenAI's agent safety guidance recommends keeping tool approvals on for MCP operations so users can review and confirm actions. It also warns that untrusted content can influence tool calls, which is why instructions alone are not a sufficient control. [OpenAI, Safety in building agents](https://developers.openai.com/api/docs/guides/agent-builder-safety)

The model may prepare a proposal. The send function should still require a decision token from an authorized person.

## Match the approver to the consequence

Approval ownership should be written before the draft exists.

- A support lead approves customer replies and policy exceptions.
- The account owner approves a client-facing deliverable.
- A communications owner approves public posts.
- The budget owner approves purchases, charges, refunds, and price changes.
- The system owner approves production deployment or activation.
- The record owner approves consequential CRM changes.

One person may hold several roles in a small company. The roles should remain distinct in the file because each action carries a different check.

NIST's AI RMF, a voluntary framework, describes defined human oversight roles and documented processes for override, incident response, recovery, and change management as an outcome. [NIST AI RMF Core](https://airc.nist.gov/airmf-resources/airmf/5-sec-core/)

## Show the full action preview

An approval screen or file should show:

- action type;
- destination or recipient;
- sending account;
- exact final text;
- attachments or linked records;
- material claims and their sources;
- expected side effect;
- expiration time;
- rollback or correction path, when one exists.

"Approve email?" is too thin. The reviewer should not need to open five systems to learn what the approval means.

## Do not bundle unrelated actions

Approving an email does not approve a CRM update. Approving a draft does not approve publication. Approving a booking does not approve payment. For reducing approval volume while preserving the action boundary, read [Approval Fatigue: Reduce AI Agent Approval Requests.](/articles/prevent-ai-agent-approval-fatigue)

Bundle only actions that the reviewer can understand as one consequence. If the workflow would send a proposal, update a pipeline stage, and create a calendar event, show three actions. Each can have its own approver or result.

## The file to inspect

Create `approvals/APR-2026-0817-0042.yaml`:

```yaml
approval_id: APR-2026-0817-0042
status: pending
action: send_email
account: support@example.com
recipient: customer@example.net
subject: Your requested account summary
body_path: drafts/TKT-1842-email.md
attachments:
  - exports/TKT-1842-account-summary.pdf
claims_source:
  - customers/C-1842/account-record.md
  - policies/support-current.md
approver_role: support_lead
expires_at: 2026-08-18T17:00:00-04:00
on_approve: permit this one send
on_reject: retain draft and record reason
```

The send tool consumes only an approved, unexpired record whose recipient, account, body hash, and attachments still match. If any field changes, approval becomes invalid.

## Bind approval to the exact artifact

Approval should cover an immutable description of the proposed action.

Hash the final body or store it in a versioned location. Record the recipient, sending account, subject, attachments, and material claims. The executor compares the current action with the approved record before it receives the credential.

If a person edits the draft after approval, the body hash changes. If an attachment is replaced, its hash changes. If the workflow selects a different account or recipient, the identifiers change. Each mismatch invalidates approval.

This prevents a common race: a reviewer approves one version while the agent or another person continues editing it.

## Make permission narrow and one-time

An approval record should not become a standing permission unless the workflow was deliberately designed for recurring authority.

For a single send, use an approval ID that can be consumed once. The executor records the attempt and result against that ID. A retry after an uncertain response should read external state or request a new decision, not assume the first send failed.

The executor can enforce:

```text
approval_status:: approved
permitted_action:: send_email
permitted_account:: support@example.com
permitted_recipient:: customer@example.net
artifact_hash:: sha256:...
expires_at:: 2026.08.18T17:00:00-04:00
maximum_attempts:: 1
consumed_at:: empty until execution
```

The model does not generate or validate its own approval. The capability checks a record from the authorized approval path.

## Handle rejection and expiration as normal states

A rejected action is not a system failure. Preserve the draft, record the reason, and route any reusable correction to review.

An expired approval also creates a stop. The workflow can prepare a fresh preview, but it cannot extend the deadline for itself. If the sending account, recipient, claim, or attachment changes, require a new approval even when the old record has not expired.

These states should appear in receipts and operational dashboards. Hiding rejections makes it harder to see where a workflow needs better sources or clearer rules.

## Record the decision

After the decision, write a receipt containing the approval ID, decision, approver identity, time, action hash, and send result. A refusal is also a valid receipt.

Do not put passwords, access tokens, or excess personal data in the receipt. The purpose is to prove the decision path, not copy every sensitive field into a log.

## Verify the effect after execution

An accepted API response may not prove the intended action exists in the intended place.

When the connected system permits it, read back the message ID, publication URL, booking record, deployment version, or CRM change. Compare the recipient, account, artifact, and resulting state with the approval record.

If read-back fails, record an uncertain or failed result. Do not tell the reviewer the action succeeded because the request returned without an error.

## Define delegation before the approver is absent

An approval path that depends on one unavailable person can stop legitimate work or invite someone to bypass the gate.

The approval map should name whether delegation is allowed, which role may receive it, the time window, and which action classes remain nondelegable. A support lead may delegate routine customer replies while the budget owner keeps refund authority. A system owner may delegate a staging deployment while production activation stays with the named owner.

Record delegation outside the draft being approved:

```text
delegated_role:: acting support lead

delegation_id:: DEL-SYNTHETIC-2026-0818-01
revoked_at:: null
revocation_check:: consult current delegation registry before execution
delegated_by:: support lead
valid_from:: 2026.08.18T09:00:00-04:00
valid_until:: 2026.08.22T17:00:00-04:00
permitted_actions:: customer reply approval
excluded_actions:: refunds, credits, contract exceptions
```

The executor checks the delegation record just as it checks the action record. The agent cannot appoint its own reviewer or widen a delegate's authority.

The action receipt records `delegation_id`, the checked registry version, and the revocation result. An expired, revoked, or unavailable delegation record cannot authorize the action.

## The stopping point

The preparation agent follows the [tested stopping-rule examples](/articles/ai-agent-stopping-rules-examples) and stops after it creates the action preview. It must stop earlier when the recipient, account, material claim, attachment, or approver is unresolved.

It must not send, publish, book, spend, deploy, or change a CRM record on its own. A separate executor may perform one exact approved action. Changed scope requires a new approval record.

## Smallest fitting next step

If you need to place the approval gate in one workflow, write the workflow into a brief first. Preparing the [six-question brief](/work#prepare-your-six-question-brief) needs no purchase. [Send your brief](/work) For the owned-system approach behind that next step, inspect [Scale With Search: AI Systems You Own.](/)


## Questions about Who Approves What an AI Agent Sends?

### What did the person approve?

Approval should cover the exact action, not only the agent's explanation or the general intent. Show the action type, destination, sending account, final text, attachments, linked records, material claims, expiry, and correction path.

### How tightly are people binding human approval to the action that eventually happens?

Bind approval to an immutable description of the proposed action, including the recipient, account, subject, attachments, material claims, and artifact hash. If any material field changes, the approval becomes invalid and the workflow must create a fresh preview.

### For people running human-in-the-loop outreach, do you review every message or only drafts below a confidence threshold?

The approval map should assign ownership by consequence and capability. Safe preparation can run inside its contract, but the executor should require an authorized decision for the exact external send.

### How are you handling human approvals in your agent workflows?

Use a short-lived, one-time approval record tied to the exact action, account, destination, artifact, and expiry. After execution, record the decision and read back the resulting message, booking, deployment, or record state when the connected system permits it.

## Save the visual summary

Show the full action preview | Bind approval to the exact artifact | Make permission narrow and one-time | Record the decision

[Download the PNG](/infographics/who-approves-what-an-ai-agent-sends-1200x1500.png)


## Related: Agent Governance

- [When an AI Workflow Should Stay Manual](/articles/when-an-ai-workflow-should-stay-manual)
- [The Trust Gap Is the Approval Gap](/articles/trust-gap-adoption-gap)
- [The Complete Small-Business Guide to AI Agent Governance](/articles/ai-agent-governance-guide-small-business)

----

```text
                  .|########||.                                       .|########||.                                       .|########||.
               |##||.      .||##|.                                 |##||.      .||##|.                                 |##||.      .||##|.
             |#|.              .|#|.                             |#|.              .|#|.                             |#|.              .|#|.
           |#|                    |#|                          |#|                    |#|                          |#|                    |#|
         .#|                        |#.                      .#|                        |#.                      .#|                        |#.
        .#.                          .#|                    .#.                          .#|                    .#.                          .#|
       |#.                            .#|                  |#.                            .#|                  |#.                            .#|
      |#             ......             #|                |#             ......             #|                |#             ......             #|
     .#           ||#########|           #|              .#           ||#########|           #|              .#           ||#########|           #|
    .#.         |######||######|.        .#.            .#.         |######||######|.        .#.            .#.         |######||######|.        .#.
    #.        .##|###|##|#|######|        .#            #.        .##|###|##|#|######|        .#            #.        .##|###|##|#|######|        .#
   ||        |##|#||||||||||||#||#|        ||          ||        |##|#||||||||||||#||#|        ||          ||        |##|#||||||||||||#||#|        ||
   #        |#||||||||||||||||||||#|        #.         #        |#||||||||||||||||||||#|        #.         #        |#||||||||||||||||||||#|        #.
  ||       |#||||||||||||||||||||||#|       ||        ||       |#||||||||||||||||||||||#|       ||        ||       |#||||||||||||||||||||||#|       ||
  #       .#||||||||||||||||||||||||#|       #        #       .#||||||||||||||||||||||||#|       #        #       .#||||||||||||||||||||||||#|       #
 ||   ....|||#||||||##|#|||#|#||##||||....|. ||      ||   ....|||#||||||##|#|||#|#||##||||....|. ||      ||   ....|||#||||||##|#|||#|#||##||||....|. ||
 #.  .  ....|#  ....#|||   ||| .#|||  ....#. .#      #.  .  ....|#  ....#|||   ||| .#|||  ....#. .#      #.  .  ....|#  ....#|||   ||| .#|||  ....#. .#
 #   .  ||||#| .#####||  . .#| .#|||  ||||#   #.     #   .  ||||#| .#####||  . .#| .#|||  ||||#   #.     #   .  ||||#| .#####||  . .#| .#|||  ||||#   #.
.|   |||||  #. |#|||||. ||  #. |#||. .|||||   ||    .|   |||||  #. |#|||||. ||  #. |#||. .|||||   ||    .|   |||||  #. |#|||||. ||  #. |#||. .|||||   ||
||   |....  #. ....|#.      |. ...|. ....||   ||    ||   |....  #. ....|#.      |. ...|. ....||   ||    ||   |....  #. ....|#.      |. ...|. ....||   ||
#.  .||||||##||||||##||####|||||||#||||||#|   .#    #.  .||||||##||||||##||####|||||||#||||||#|   .#    #.  .||||||##||||||##||####|||||||#||||||#|   .#
#    .||####|###########################|.     #    #    .||####|###########################|.     #    #    .||####|###########################|.     #
#      .#||||||.#.|| # |. ..# #| #|||||#|      #    #      .#||||||.#.|| # |. ..# #| #|||||#|      #    #      .#||||||.#.|| # |. ..# #| #|||||#|      #
#      .#|||||| ..  |# ## |#| ...#|#|||#|      #    #      .#|||||| ..  |# ## |#| ...#|#|||#|      #    #      .#|||||| ..  |# ## |#| ...#|#|||#|      #
#      .#|||#|# .# .#| #| ##|.#..#|||||#|      #    #      .#|||#|# .# .#| #| ##|.#..#|||||#|      #    #      .#|||#|# .# .#| #| ##|.#..#|||||#|      #
#      .#||||||############|######|||||#|      #    #      .#||||||############|######|||||#|      #    #      .#||||||############|######|||||#|      #
#   |...||#||||||#||||#|#||||||#|||||#||| |.|  #    #   |...||#||||||#||||#|#||||||#|||||#||| |.|  #    #   |...||#||||||#||||#|#||||||#|||||#||| |.|  #
#. .. ||||# .|||##|.  |#| .|| || .|||#. #|  # .#    #. .. ||||# .|||##|.  |#| .|| || .|||#. #|  # .#    #. .. ||||# .|||##|.  |#| .|| || .|||#. #|  # .#
|| |  ...||  ...##| |  #| .|. |. #####  .. .| ||    || |  ...||  ...##| |  #| .|. |. #####  .. .| ||    || |  ...||  ...##| |  #| .|. |. #####  .. .| ||
|| ||||| || ||||#|  .  |. |. |#. ||||| |#| || ||    || ||||| || ||||#|  .  |. |. |#. ||||| |#| || ||    || ||||| || ||||#|  .  |. |. |#. ||||| |#| || ||
.# |.....#|....|#.||||.|||##.|#|....||.#||.#. #.    .# |.....#|....|#.||||.|||##.|#|....||.#||.#. #.    .# |.....#|....|#.||||.|||##.|#|....||.#||.#. #.
 #.|||||||#############################| ||| .#      #.|||||||#############################| ||| .#      #.|||||||#############################| ||| .#
 ||       ##||#||#||||||#||#||#||#||##.      ||      ||       ##||#||#||||||#||#||#||#||##.      ||      ||       ##||#||#||||||#||#||#||#||##.      ||
  #       .#|||||||||#||#|||||||||||#|       #        #       .#|||||||||#||#|||||||||||#|       #        #       .#|||||||||#||#|||||||||||#|       #
  ||       |#||||||||||||||||||||||#|       ||        ||       |#||||||||||||||||||||||#|       ||        ||       |#||||||||||||||||||||||#|       ||
  .#        |#||||||||||||||||||||#|        #.        .#        |#||||||||||||||||||||#|        #.        .#        |#||||||||||||||||||||#|        #.
   ||        |#||||||||||||||||||#|        ||          ||        |#||||||||||||||||||#|        ||          ||        |#||||||||||||||||||#|        ||
    #.        .######|#|#########|        .#            #.        .######|#|#########|        .#            #.        .######|#|#########|        .#
    .#.         |#####||||#####|         .#.            .#.         |#####||||#####|         .#.            .#.         |#####||||#####|         .#.
     |#           ||########||           #.              |#           ||########||           #.              |#           ||########||           #.
      |#             ......             #|                |#             ......             #|                |#             ......             #|
       |#.                            .#|                  |#.                            .#|                  |#.                            .#|
        |#.                          .#.                    |#.                          .#.                    |#.                          .#.
         .#|                        |#.                      .#|                        |#.                      .#|                        |#.
           |#|                    |#|                          |#|                    |#|                          |#|                    |#|
            .|#|.              .|#|.                            .|#|.              .|#|.                            .|#|.              .|#|.
               |##||.      .||##|                                  |##||.      .||##|                                  |##||.      .||##|
                 .||########||.                                      .||########||.                                      .||########||.

Scale With Search  2026  [scalewithsearch.com](https://scalewithsearch.com)
```
