# How to Set Approval Rules So AI Never Acts Alone *How-to — 2026-09-28 — by Mahmoud Zalt* Build approval rules that stop AI on risky actions without drowning you in prompts: which actions to gate and how to avoid rubber stamping. **Short answer.** **Gate the actions you cannot undo, and let everything else run. **That means approval on anything that reaches someone outside your company, moves money, deletes records, changes access, or touches more than a handful of items at once. Keep the gated list short so each prompt still gets read. A gate on everything is the same as no gate at all. The fear of an AI acting alone is really a fear of one specific moment: the message that reached a customer before you saw it. Everything else it does is recoverable, and you know it. So the design job is not to supervise everything. It is to identify the small set of actions where after the fact detection is worthless, and to make those stop and wait. Get that list right and you can let the AI Employee run freely everywhere else without a knot in your stomach. On **Sistava**, approval is a property of the action, not a mode you switch on. Each capability an AI Employee has is marked as either safe to run or requiring a human yes, and the risky ones ship gated by default. When one comes up, the work pauses, you get a prompt showing exactly what is about to happen, and nothing moves until you answer. ## At a Glance - **5** Action types that should always be gated - **Default** Gated is the shipping state, not an add-on - **Paused** What the AI Employee does while it waits - **Under 10** Prompts a week in a healthy setup ## Which actions should always need your approval? Five categories, and the test for each is the same: if this goes wrong, can I quietly fix it in ten minutes? Anything reaching a person outside your company, anything moving money, anything deleting, anything changing who has access, and anything touching many records at once. Those five fail the test. The bulk one surprises people. A single wrong record is a shrug. The same mistake applied to four hundred customer records at machine speed is a bad week. Volume turns a small error into an incident, so a count threshold deserves a gate of its own even when the action type is otherwise harmless. - **Leaves the building. **Any email, message, or post that reaches a customer, supplier, or the public. - **Moves money. **Refunds, payments, credits, subscription changes, anything with a currency attached. - **Deletes. **Records, files, threads, calendar entries. Deletion is the one action with no natural undo. - **Changes access. **Inviting a user, changing a role, connecting a new tool, widening a permission. - **Touches many at once. **Any action applied above the count you choose, even when a single one would be fine. ## What should an approval prompt actually show you? A good prompt shows the exact thing that will happen, not a summary of it. The full text of the message, the real recipient, the amount, the number of records affected, and why the AI Employee decided to do it. If you have to open something else to judge the request, the prompt has failed. The reason line matters more than people expect. It is where you catch a request that looks fine on the surface but was triggered by something odd, like an instruction buried inside an incoming document. A message that reads perfectly well can still be the wrong message to send, and the reason is what tells you which. > The prompt has to contain everything you need to say no. If saying no requires research, you will say yes. > > The rule I design approval flows around ## How do you stop approvals becoming rubber stamps? You keep the number low enough that each prompt is still an event. If you get five a week you read them properly. If you get fifty a day you tap approve while walking, and the gate is now decoration. Approval fatigue is not a personal failing, it is a predictable result of gating too much. Getting the number down means being deliberate about categories rather than loosening standards. Let internal messages run without approval. Let read-only work run. Let drafts pile up freely. Reserve the interruption for the five categories, then tune the thresholds until the weekly count feels readable rather than ignorable. Sam leads customer success at a forty five person software company in Austin, and he tuned this over about six weeks. Week one he gated everything and got roughly ninety prompts, which he admits he stopped reading by Wednesday. He then removed the gate from internal Slack messages and from drafting, which cut it to about thirty. Then he allowed order status and password reset replies to send on their own, since both are easy to correct, and landed near seven prompts a week. Refunds, cancellations, and anything to an enterprise account are still gated and always will be. Seven he reads. Ninety he did not. ## What happens when you say no? The action does not happen, the AI Employee records the refusal, and it continues with the rest of its work. You can add a note explaining why, and that note shapes how it handles the same situation next time. Declining is not a failure state, it is ordinary feedback. If a prompt is waiting and you are busy, the work simply sits paused. Nothing times out into approval, and nothing decides to proceed because it seemed urgent. Silence is never a yes, which is the property that makes the whole gate meaningful. Two honest limits. Approvals only protect you if you read them, so tuning the count is a safety task rather than a comfort task. And an approval you grant is a decision you own, which means the gate moves responsibility to you rather than removing it. That is the correct place for it, but it should be said plainly rather than sold as a magic shield. ### Set your approval rules in half an hour 1. **1. Write your irreversible list** — Go through what the AI Employee will handle and mark anything you could not quietly fix in ten minutes. That is your gated list. 2. **2. Gate the five categories first** — External messages, money, deletion, access changes, and bulk actions. Start here even before you know your own edge cases. 3. **3. Pick a bulk threshold** — Choose the number of records above which anything stops for review. Ten is a reasonable starting point for a small team. 4. **4. Leave everything else ungated** — Internal messages, reading, research, drafting, and scheduling can run freely. Protect the interruption budget for what matters. 5. **5. Count your prompts after one week** — If the number is too high to read carefully, loosen one low risk category. Repeat until the count is one you genuinely read. 6. **6. Re-check the list each quarter** — New tools and new duties bring new irreversible actions. Fifteen minutes every few months keeps the gate matched to the work. ## Comparison | Dimension | Traditional | With Sista | |---|---|---| | Prompts per week | Dozens, often hundreds | A handful you actually read | | How prompts get answered | Approved on reflex within days | Read, considered, sometimes declined | | Real protection | Low, because attention ran out | High, because attention is concentrated | | Speed of the work | Everything waits on you | Safe work runs, risky work waits | | How it feels after a month | Noise you have learned to ignore | A short list worth opening | ## FAQ ### Does an approval gate slow the AI Employee down? Only on gated actions. Everything else runs at full speed, which is why the gated list should stay short. Most of the work an AI Employee does, reading, researching, preparing, and drafting, never touches an approval at all. ### Can different teammates approve different things? Yes, and you should set it that way. Route refunds to whoever owns finance, customer messages to whoever owns support, and access changes to an admin. Approvals sent to everyone get answered by no one. ### What if nobody responds to a prompt? The task stays paused indefinitely. Nothing proceeds on a timeout, because an action that happens when you are not looking is exactly what the gate exists to prevent. ### Can I approve a whole category once instead of each time? You can remove the gate from a category deliberately, which is a different thing from a blanket yes on a single prompt. One prompt approves one action, and that separation is what keeps a single tap from widening authority permanently. ### Do approvals help against manipulated instructions? They are the main defence. Text hidden inside an incoming document can influence what the AI Employee proposes, but it cannot approve anything. A strange outbound request lands in front of you, and you say no. ### Where do I see what was approved and what was declined? In the action log, alongside every other action, with the decision and any note you added. That record is what makes it possible to review your own gates and see whether they are set at the right level. **Tags:** ai-approvals, human-in-the-loop, ai-guardrails, ai-safety, ai-employee