An AI agent can research, draft, and plan without changing the world around you. The important boundary appears when a proposal becomes a real action.
A useful confirmation should make that boundary clear. It should help you catch the wrong target, content, permission, timing, or consequence before the action happens.
The short answer
Before an AI agent takes a consequential action, it should confirm five things: the action, the target, the exact payload, the consequence, and the permission scope.
That does not mean asking before every search, summary, or draft. Ask when the next step will send, share, buy, delete, publish, schedule, change access, or otherwise affect someone or something outside the current draft. The person should still be able to understand the choice, correct it, and stop it.
After the action, the agent should show a receipt: what happened, where, when, and what can still be undone.
| Job | Useful default | Why |
|---|---|---|
| Read or search within allowed sources | Proceed and cite the sources | No state change, though access still needs boundaries |
| Draft or propose a change | Prepare it for review | The person can inspect the result without committing it |
| Make a small reversible local change | Follow the chosen approval setting and show the diff | A real undo path can reduce interruption |
| Send, share, publish, or schedule | Pause with the exact destination and content | The action reaches another person or system |
| Delete, pay, change permissions, or accept terms | Pause or refuse, depending on the risk | The consequence may be difficult or impossible to reverse |
This table is a practical model, not a universal standard. The same action can carry different consequences in different contexts.
The five-part check
A generic “Continue?” prompt is usually too thin. The person needs enough information to make a real decision.
1. The action
Say what the agent is about to do in a verb that matches the consequence.
“Send,” “share,” “delete,” “buy,” and “grant access” are clearer than “continue” or “run.” Apple’s App Intents framework includes action-specific confirmation labels for the same reason: the confirmation should name the operation, not hide it behind a vague button.
2. The target
Show the exact person, file, account, calendar, workspace, or record that will change.
The action may be correct while the target is wrong. “Email the update” is incomplete if two clients have similar names. “Delete this note” is incomplete if the user cannot see the note title or path.
When the target is uncertain, ask the person to resolve the target before asking them to approve the action.
3. The payload
Show the content or value that will be used.
For a message, that means the recipients, subject, body, attachments, and any sensitive context being shared. For a calendar event, it means the time, time zone, guests, location, and description. For a purchase, it means the item, quantity, seller, total, and delivery details.
Do not make the person approve an invisible payload.
4. The consequence
Explain the material side effect in plain language.
Who will see the result? Will a notification fire? Will money move? Will a public page change? Will access expand? Is the action immediate or scheduled? Can it be reversed without asking another person or administrator?
“Undo available” is only useful when the undo is real, visible, and appropriate to the consequence. Recalling an email is not the same as preventing it from being sent.
5. The scope
Make clear how much permission the confirmation grants.
The safest useful scope is usually one action. Some repeated low-risk work may justify permission for a session or a narrowly defined routine. A standing permission should name the tool, target, allowed action, and limit rather than becoming a blank cheque.
“Always allow” is not a small convenience when the target can change.
When to pause
Confirmation is valuable when it changes the outcome. It is noise when the person has no useful choice to make.
A good pause usually has at least one of these conditions:
- The instruction is incomplete in a way that can change the result.
- More than one person, file, account, or record could be the target.
- Data will leave the current workspace or be shared with someone else.
- Another person will receive a message, invitation, request, or commitment.
- Money, permissions, public content, or legal terms will change.
- The action is destructive, difficult to reverse, or likely to create duplicate side effects.
- The agent is crossing from a draft or sandbox into a real system.
- The action goes beyond the permission already given for this task.
The trigger should follow the consequence, not the model’s confidence alone. A confident agent can still have the wrong recipient. An uncertain agent may safely draft three options without changing anything.
A draft-first workflow
Suppose you ask an agent:
Use my launch notes to prepare this week’s project update and send it to the team.
That sentence contains two different jobs.
First, the agent can search the allowed notes, cite the relevant sources, and prepare a draft. Nothing has been sent, so there is no reason to interrupt the work at every research step.
Then the agent reaches the boundary. Before sending, it should show:
- Action: Send one project-update email.
- Target: The exact recipients and whether anyone is copied.
- Payload: Subject, body, links, and attachments.
- Consequence: The message is sent immediately and becomes visible to those recipients.
- Scope: Approval applies to this email only.
You can correct the recipient list, remove a private note, rewrite a commitment, schedule the message instead, or reject the send.
Afterward, the agent should report whether the message was sent, which account sent it, who received it, and when. If the tool timed out, it should not silently retry a potentially duplicate send. It should check the result or ask.
That is the difference between a ceremonial prompt and a useful control.
Cue Agent uses a proposal-first pattern for note changes: it can prepare an update and keep the file unchanged until the person reviews and approves it. The available actions and approval controls can vary by app version, provider, and connected tool.
When not to interrupt
An agent that asks before every harmless step trains people to stop reading.
It usually does not need a new confirmation to:
- search sources it was already allowed to read;
- summarize a document without changing it;
- draft a message without sending it;
- compare options;
- calculate a result in a sandbox;
- prepare a proposed note edit;
- retry a read-only request that had no side effect.
A prior permission may also cover a narrow, reversible action. For example, a person could allow edits within one scratch note for the current session while still requiring approval before deletion, sharing, or any external action.
The boundary should remain visible. Cue MCP describes access as scoped and user-initiated: the agent gets the context the person chooses to connect, not an implied right to everything.
Limits
Confirmation is not the same as safety.
A well-designed prompt can still show stale information, omit a hidden consequence, or be influenced by malicious content. The model can misunderstand the instruction. The tool can fail after partially completing the action. A tired person can approve without reading.
Use confirmation with other controls:
- limit the agent to the data and tools needed for the task;
- keep sensitive actions structurally unavailable when they are out of scope;
- show sources and proposed changes;
- separate preparation from execution;
- prevent blind retries of side-effecting calls;
- record the completed action;
- provide a real stop, reject, and undo path;
- test what happens when context is missing, stale, or contradictory.
OpenAI describes confirmations as one safeguard for consequential actions, not a guarantee that prompt injection or mistakes cannot happen. NIST’s AI risk guidance similarly treats human oversight as something to define according to the capability, context, and risk—not as a checkbox added to every interaction.
Cue may not be the right tool when you need a specialist approval system, regulated workflow, organization-wide policy engine, or a guarantee that a human reviewed every possible consequence. Use the system that owns the action and its controls.
FAQ
Should an AI agent ask before every action?
No. Read-only research, summaries, calculations, and drafts can usually proceed within an already approved scope. Ask near a meaningful state change or when missing information can materially change the result.
What counts as a consequential action?
Common examples include sending or publishing content, sharing data, creating an external commitment, moving money, deleting data, changing permissions, accepting terms, or touching production systems. The context matters: even a calendar invite can be consequential when it reaches the wrong people.
Is human confirmation enough to make an agent safe?
No. Confirmation can reduce some mistakes only when the person can inspect the relevant details and still stop the action. Access controls, limited tools, testing, receipts, and recovery paths still matter.
Do reversible actions need confirmation?
Sometimes. A reliable, visible undo path can justify fewer interruptions for a low-consequence local change. It does not make every action reversible. External messages, permission changes, and financial commitments can create effects that an undo button cannot fully remove.
How broad should an approval be?
Prefer the narrowest scope that lets the work continue: one action, one exact target, or one bounded session. Standing permission should be deliberate and specific. Avoid permission that silently expands to new targets or tools.
How does Cue handle agent actions?
Cue’s public Agent page shows sourced answers and proposed note changes that remain unchanged until review and approval. That note-editing workflow should not be read as a promise that every connected tool or unattended action has the same controls. Check the permissions and review behavior for the action you intend to take.
For the context side of the same decision, read local notes and cloud models can work together.
Sources
Sources checked October 4, 2026.
- OpenAI: Understanding prompt injections
- OpenAI: Introducing ChatGPT agent
- OpenAI: ChatGPT agent system card — user confirmations
- Apple Developer: Requesting confirmation for an App Intent
- Apple Developer: Confirmation action names
- NIST: AI risk management and human–AI interaction
- Cue Agent
- Cue MCP
Try the proposal first
Use Cue Notes for a low-consequence test.
Ask Cue to prepare one note change. Inspect the exact proposal. Approve it, reject it, or keep the file unchanged. Then check the note itself.
Download Cue for Mac when you want voice, notes, and reviewable AI work in one workspace.
