THE SHORT ANSWER
Put approval where an action creates material consequences or crosses an authority boundary: sending an external message, changing an authoritative record, granting access, committing money, or making a sensitive decision. The exact threshold depends on the context and the organization's risk tolerance.
Keep four states distinct
An AI system can observe data, infer a possible explanation, recommend an action, and execute an action. Those are different states. The interface should show which state the user is seeing and who is accountable for moving to the next one. A generated sentence should not look like a verified fact; a drafted action should not look complete before it is authorized.
The NIST AI framework identifies accountability, transparency, reliability, privacy, security, and other characteristics of trustworthy systems. In practice, these qualities depend on the workflow and its human roles, not only the model.
Constrain data and tools
Give the system only the data and tool access needed for the task. Separate read permissions from write permissions. Define retention and logging for sensitive inputs. If the system uses external services, understand where data goes and what third parties can do with it. The organization should be able to revoke access and trace actions.
Approval should show the evidence needed for a real decision: source material, proposed change, affected record or person, and what will happen after confirmation. A button without context is not meaningful oversight.
Make failure legible
When evidence is missing, a tool fails, or an action has uncertain status, show that state plainly. Give operators a way to stop, correct, retry, or reverse where possible. Logging an action matters, but so does making the current truth visible to the person who depends on it.
Illustrative example: an agent drafts a vendor email and proposes updating the bank's vendor record. The user can edit and send the email, but the record change needs a separate approval showing the old value, new value, source, and approver.
Original sources
The process explanations above are educational summaries. The linked primary sources govern their own terms and can change; check them for current requirements.