Agents & tools · Glossary term

What is Approval Gate?

A control point that blocks a consequential action until an authorized person or policy grants permission.

Why does Approval Gate matter?

It limits the blast radius of uncertain model decisions while preserving automation for reversible work.

Approval Gate in practice

Let an agent draft a database migration and run it against a disposable database, but require an owner to approve any production execution.

What is the common confusion about Approval Gate?

An approval gate asks whether an action is authorized. A verification gate asks whether evidence shows the action is correct.

Learn Approval Gate in the course

Start with

  • Verification Gates

    The agent does not get to mark its own work as done. A verification gate reads the scope contract, the feedback log, the rule report, and the diff, and answers a single question: is this task…

    Phase 14: Agent Engineering

Taught in Phase 14: Agent Engineering.

  • Human-in-the-Loop (HITL)A workflow design in which a person supplies judgment, correction, approval, or escalation at defined points in an AI-driven process.
  • Verification GateA control point that blocks progress until defined evidence satisfies a correctness or quality criterion.
  • Least PrivilegeGiving a model, agent, tool, or user only the permissions required for the current task, for only as long as those permissions are needed.
  • Audit LogA durable, access-controlled record of security- or accountability-relevant events, including who or what acted, what changed, when it…
  • Compensating ActionA deliberate operation that semantically counteracts a completed side effect when the original operation cannot be rolled back atomically.
  • Durable ExecutionRunning a workflow so its state and completed steps survive process crashes, restarts, or long waits without redoing confirmed side effects.
  • GuardrailsSystem controls that constrain inputs, tool use, outputs, permissions, and escalation.
  • Prompt InjectionAn attack or failure mode in which untrusted content influences a model to disregard intended instructions, expose data, misuse tools, or…
  • SandboxAn isolated execution environment that restricts an agent's access to files, processes, network destinations, credentials, and host…
  • Separation of DutiesDividing conflicting responsibilities or authority across independent roles so one principal cannot complete a high-risk action without…
  • Skill InvocationThe runtime-mediated process in which an eligible human, model, application, or other skill selects a skill and causes its instructions to…
  • Zero TrustA security model that grants no implicit trust from network location or asset ownership and instead evaluates each access request against…

More terms in Agents & tools

Open the Agents & tools list in the glossary

This entry comes from glossary/terms.md on GitHub. Browse all 250 glossary terms.