The short answer
Don’t let your agent send directly. Route outbound emails through an approval layer — either a pre-send webhook that gates every message, a draft queue that humans review, or a confidence threshold that decides automatically. The right pattern depends on how much you trust your agent and how high the stakes are.Why this matters
Every enterprise conversation about AI agents eventually lands here. “What if it says something wrong?” is the question that blocks deployment. The answer isn’t “trust the model” — it’s “build a gate.” Human-in-the-loop approval is not about slowing your agent down. It’s about making the humans around it comfortable enough to let it run. Start strict, loosen over time as confidence builds.Pattern 1: Pre-send webhook
Your agent doesn’t callcommune.messages.send() directly. Instead, it posts the draft to your own approval endpoint. A human (or an automated policy check) approves or rejects. Only approved messages get sent.
Pattern 2: Confidence thresholds
Your agent outputs a confidence score with every draft. High-confidence messages send automatically. Low-confidence messages go to a review queue.Pattern 3: Escalation rules
Some emails should always require approval, regardless of confidence. Define rules based on recipient, content, or context.Combining the patterns
In practice, you’ll use all three together. The decision tree looks like this:
Start with everything going through review. As you build confidence in your agent, relax the rules:
- Week 1-2: Approve every email manually. Build a dataset of what your agent sends.
- Week 3-4: Auto-approve replies in existing threads with confidence > 0.95.
- Month 2: Auto-approve all emails except those matching escalation rules.
- Ongoing: Review escalation rules quarterly. Add new ones when you discover edge cases.
Approval queue timeout
Don’t let drafts sit in the queue forever. Set a TTL — if nobody reviews within 2 hours, either auto-reject or auto-send with a flag.Related
Webhooks
Full webhook reference for building event-driven approval workflows.
What happens if my agent sends something wrong?
Damage control and incident response when an email goes out that shouldn’t have.
Rate Limits
Rate limiting as an additional safety layer to prevent burst damage.
Preventing Data Leakage
Stop your agent from including sensitive data in outbound emails.

