← All insights

Andrew Leonenko · October 2026

Agent workflows need control points, not just prompts

How to give AI agents useful autonomy while keeping permissions, human review, and retries inside clear boundaries.

Agent workflow with a human approval checkpoint.
Agent workflow with a human approval checkpoint.

Agent demos make autonomy look like a property of the model: give it a goal, a set of tools, and let it run. Production systems make the question more concrete: which decisions can the software make on its own, which actions need a person, and how do we recover when either side is wrong?

A useful agent is not a prompt connected to every capability in an application. It is a workflow with explicit boundaries.

Separate planning from permission

Let a model propose an action; let application code decide whether that action is allowed. For example, an assistant can draft a refund recommendation, but the service should still check the order, policy, amount limit, and caller's role before any refund is issued.

That split is valuable because model output is probabilistic while authorization should be deterministic. Tool schemas can constrain the shape of a request, but they do not replace identity checks, business rules, or data access controls.

Make approval proportional to impact

Not every step needs a confirmation dialog. Read-only lookups and reversible drafts can usually proceed within a narrow scope. Actions that move money, change access, contact a customer, or publish content deserve stronger review.

A practical control point records four things: what the agent wants to do, why it selected that action, what data it used, and what will happen if approved. The reviewer should be able to approve, reject, or revise the proposed action without reconstructing the entire conversation.

Design for interruption

Human review changes the execution model. A workflow may pause for minutes or days. Store the proposed action and its context durably, give it an expiration policy, and re-check permissions and relevant business state when the workflow resumes. Do not assume that an approval remains valid after the underlying account or record changes.

Treat retries as a product decision

A timeout does not always mean an action failed. Before retrying an operation, the system needs an idempotency strategy or a way to inspect whether the first attempt succeeded. Otherwise, a retry can create duplicate transactions or messages.

The same discipline applies to agents: bound the number of steps, make tool results explicit, keep an audit trail, and provide a clear stop path.

A simple design checklist

The goal is not to put a human in every loop. It is to build a system where autonomy has a defined scope and a person can intervene at the points that matter.

Illustration: agent workflow with a human approval checkpoint.