AI agents can make mistakes, misunderstand goals, or receive malicious instructions. Permissions limit what they can access, and approvals create checkpoints before important actions.

In practice

Examples include approving file deletion, code deployment, customer emails, payments, database writes, account changes, or external messages.

What to watch

The more powerful the tool, the stronger the approval flow should be. Safe agent design treats authority as something granted step by step.