AI Agent Approval: How We Let Our Agents Publish on Their Own, and the One Switch We Kept
Our small company runs on AI agents. They research topics, write drafts, make thumbnails, fact-check, and publish to this blog. Until today, the one thing only a human did was click "approve."
On September 30, 2026, our founder asked for that to go too: approve it yourselves and just post it. This post is about how we designed that permission, what the approval step had actually caught, and the one control we refused to automate. This post was published under the new rules.
The request: "just post it yourself"
Our founder isn't a developer. Every post needed two clicks on our internal dashboard, and they wanted the agent to handle those too.
The first attempt failed in an instructive way. Our main agent (Claude Code) tried to record the approval on the founder's behalf, and the agent tool's own safety check blocked it. It treated an agent writing a human's approval as something it shouldn't do alone. The same check blocked two more steps that day. In the end, the founder had to edit the tool's permission allow-list personally before the new setup could be built.
That turned out to be the right shape for the whole design: a human grants the permission, and the agent uses it.
Why every post needed two approvals
Our workflow had two gates:
- Topic proposal. The agent researches search demand and proposes a topic and outline. Approval means "start writing."
- Publish approval. After drafting, review, and thumbnails, approval means "put it online."
Our publishing script refuses to run unless there's an approved item whose text contains "publish approval" (in Korean, in our system). Publishing is public and hard to take back, so that's where the hard stop lives.
What the gate actually caught
The approval step wasn't ceremony. From our records:
- A permission bug in our own code. While reviewing the publisher, we found it accepted *any* approval, so a topic approval alone could have published a post. Nothing was published that way; we fixed it the same day.
- A wrong paste. Before we automated publishing, a page's content was pasted into the wrong page because the copy button didn't show which file it held. Since then, every publish is followed by fetching the live page and comparing the title, headings, and image.
- Unsupported claims. Our reviewer agent flagged at least one sentence our records didn't support in five of our six publishing rounds.
The switch only a human can flip
Here's what we built:
- Each task has a delegation flag. When it's on, the agent records both approvals itself and publishes.
- The flag turns on when the founder checks "handle everything" on the dashboard, or asks in chat to post automatically. In the chat case, the agent must record the founder's exact words in the task log.
- Only the founder can turn it off, with one button on the task page. The publishing script checks the flag again right before posting. If delegation was revoked, auto-approvals no longer count.
Turning autonomy on is easy. Turning it off is always one click away, and the record shows who asked for what.
Where automation still stops
Delegation doesn't mean "never ask." The agent stops and reports when:
- the reviewer still fails the draft after two rounds of fixes,
- the topic is health or finance (content that can affect people's lives or money),
- the post-publish check doesn't match what was approved,
- or delegation was switched off mid-task.
And the scope is narrow on purpose: blog topic and publish approvals only. The approval command refuses anything mentioning payments, sales, pricing, or account settings, whether or not delegation is on.
A permission checklist for small AI teams
Before handing an agent a new permission, we ask:
| Question | For our blog posts |
|---|---|
| Can a mistake be undone? | Yes. Posts can be edited or taken down |
| Is there an automatic check against the record? | Yes. Reviewer pass + live-page comparison |
| Can a human stop it at any moment? | Yes. One "revoke" button |
| Is the human's original instruction saved? | Yes. Quoted in the task log |
| Is the scope limited in code, not just in a prompt? | Yes. Blog approvals only |
If any answer is "no," it stays a human click. For now, that's still true for everything except our blog.
*How this post was made: researched, drafted, and reviewed by AI agents, and published under the delegation described above after our founder asked for automatic posting. Everything here happened in our company between September 26 and 30, 2026.*
Comments
Post a Comment