Elderly man sitting in a rope and textile store, exuding warmth and charm.
← Ramblings

How to Tell a Real AI Approval Gate From a Checkbox

2026-09-02 · Clara F. & agents

Every AI tool selling to small businesses says some version of the same sentence right now: you're always in control, confirmation stays in your hands, nothing happens without you. It has become the safest thing to promise, and that's exactly why it's stopped telling you very much.

I read a lot of these product pages. Some vendors mean it in the one place that matters. Others mean it somewhere that barely matters at all. The homepage doesn't say which. Three questions do.

What "in your hands" is actually supposed to mean

An AI agent works in a loop. It looks at something, a new invoice request, a message from a customer, decides what to do, then acts. In a well-built system, a fourth step sits between deciding and acting: something checks the action before it lands (I explain the full loop in What is an AI "agent", actually?).

"Confirmation always stays in your hands" is a claim about that fourth step, and only that step. Does a human see the specific action before it happens, every time, for the actions that would actually cost you something if they went wrong? That's a narrow, testable claim. A product can be completely honest about oversight existing somewhere in it, while that oversight sits nowhere near the part you actually care about.

The gap that's easy to miss

I watched this gap open in a real product built for small businesses this year. The company added a page where AI assistants like ChatGPT or Claude can look up its pricing and features directly, and on that page it promises confirmation always stays with the owner. That's true, as far as it goes. The page is read-only. Nothing on it can move money or send anything under your name, so there is nothing consequential to confirm in the first place.

The part of the same product that actually runs a business, the bot that logs expenses, sends invoices and processes payments, works differently. The company's own product page describes it plainly: it doesn't discuss, it executes. Ask it to log an expense and it logs the expense. Tell it to send an invoice and the invoice goes, immediately, no pause. Only two things stop for a human check: changing the bank account on file, and changing a tax rate. Both are account settings. Neither is the money-moving action a shopper pictures when they read "always in your hands".

Nobody lied. Both sentences, on both pages, are true. The gap is that a shopper reading the homepage has no way to know which page's promise they're actually getting.

Three questions that close the gap

1. Which specific actions pause for you? Ask for the list, not the adjective. "Confirmation" and "control" are adjectives. "Before an invoice sends" is a specific action.
2. Where does the pause happen? Inside the action itself, or on a separate settings page you'd only find by going looking for it? A pause that lives in account settings protects your account. It doesn't protect your customers or your cash.
3. What does the support or technical documentation say, not the homepage? Marketing copy is written to reassure you. A support article describing what the tool does by default is written to be accurate, because someone will eventually hold the company to it.

A hardware store owner comparing two invoicing assistants asked exactly this on a signup call last month. One vendor answered in a single sentence: every invoice and payment waits for your tap before it sends, no exceptions. The other talked about "full transparency and control panels" for two minutes without naming one action that actually paused. Same homepage promise. Two different products underneath it.

Where the honest limits are

A real approval gate is only as good as the person approving. If every request gets an automatic yes without a real read (a habit worth checking honestly, see Do I Really Have to Check Everything My AI Does?), the pause is theatre either way, whether or not the vendor meant it to be.

A vague answer today doesn't always mean dishonesty, either. Some of these products are genuinely mid-build, adding real confirmation steps one feature at a time. The fair move is to ask when, in writing, and treat a dodge as your answer rather than assuming bad faith from a single sales call.

There's also no badge or certification for any of this yet. Nobody audits an AI vendor's approval claims the way a health inspector checks a kitchen. For now, you are the audit.

The one thing to do before you sign up

Pick the two or three actions in your business that would actually cost you something if they went wrong unsupervised: an invoice going out, a payment moving, a message going to a client under your name. Email the vendor and ask, plainly, whether each of those specific actions pauses for your confirmation every time, no exceptions. Keep the written answer. If it doesn't hold up once you're using the tool, that's a business decision, not a debugging problem, and you'll have the receipt.