How to Set Approval Rules for an AI Assistant
Set AI assistant approval rules around external communications, spending, account identity, and specific reviewable actions.
Quick answer
Set approval rules by separating what the assistant may prepare from what it may do externally. Define allowed actions, recipient scope, sender identity, spending limits, and exceptions. Require concrete review material before approval. Use the product's technical permission controls alongside written instructions, and verify the first real workflow before broadening authority.
Approval should help you make a decision, not force you to interpret an unfinished request. “May I handle this?” is vague. A reviewable request shows the exact message, recipients, account, timing, or transaction terms. That gives you a meaningful basis for saying yes or changing the plan.
Divide preparation and execution
Preparation can include reading authorized sources, organizing evidence, creating drafts, and proposing a plan. Execution includes sending messages, changing calendar records, or taking connected-account actions. Different steps can have different permissions within the same task.
For example, the assistant can prepare a follow-up draft while waiting for recipient approval. It should not treat your approval of the wording as approval of an unrelated mailing list or sender account. State which elements your approval covers.
Create a short policy with three groups:
- Allowed within a defined scope.
- Requires approval of a concrete action.
- Prohibited or outside the assistant's responsibility.
Avoid broad language such as “anything routine is fine” until you have defined routine in the actual workflow.
Worked example: client follow-ups
An illustrative consultancy wants help reminding clients about missing materials. The assistant may organize missing items and draft reminders. The owner wants to review the first messages and does not authorize scope discussions or new delivery promises.
A concrete approval request should include the recipient, established project thread, final copy, sender identity, and proposed send time. If the client responds with a request for additional work, the assistant should return that decision to the owner rather than continue the materials workflow as though scope were unchanged.
After several successful reviewed examples, the owner might allow a narrow reminder pattern for named clients and specific missing items. The exception rules remain important: stop on a response, avoid repeated chasers beyond the agreed cadence, and escalate any commercial question.
An approval policy template
You may read the assigned project sources and prepare internal summaries and drafts. Ask for approval before sending external messages, changing commitments, or using a new sender account. Show the final copy, recipients, account identity, and timing in each request. Do not spend money, negotiate terms, or add recipients unless separately authorized. If the action changes after approval, show the material change before proceeding. Stop recurring follow-ups when the recipient responds or I close the task.
Adapt the policy to supported product controls. Written boundaries guide the task, while technical controls enforce particular actions and account access. They should reinforce each other.
Review actual permission settings
Righthand's security page describes external communication controls as Yes, Ask, or No, and connections assigned explicitly to a Righthand. That means connection access and communication approval are separate concepts to inspect. An assigned account does not mean every conceivable action fits your task brief.
Confirm the available controls for the workflow you intend to run. Do not assume that a communication setting is a universal approval switch for all possible purchases, account changes, or third-party actions. Ask about the actual enforcement boundary when your use involves consequential operations.
Keep approvals specific and durable enough to review. If a recurring workflow is authorized, state its recipient scope, cadence, content boundaries, and stop rules. Revisit that authority when the team, accounts, or task changes.
Evaluate how the assistant handles uncertainty. It should return a blocked decision with the necessary review material, not repeatedly ask an abstract permission question or silently invent a workaround.
Frequently asked questions
Should every action require approval?
Choose based on consequence and scope. Reversible internal preparation can often proceed within the brief. External actions and commitments deserve controls appropriate to their risk and your preferences.
Can I authorize a recurring pattern?
Yes, when the product supports the actions and you specify the boundaries. Review the first examples and retain clear exception and stop rules.
What if I approved the draft but the recipient changed?
Treat recipient scope as part of the action. A material change should return for review unless it is explicitly covered by prior authority.
See task delegation and integrations for related Righthand workflow and account considerations.