Approve AI agents in Slack: the loop without the leash
Approve AI agents in Slack with one reply: gate the irreversible, delegate the rest. Publish, send, and spend wait for your yes. Drafts, research, and audits do not ask. That single rule kills the two failure modes that make agents impossible to trust.
The two ways an agent can fail
There are exactly two ways an AI agent becomes useless to you, and they are opposites.
An agent that posts without asking. It drafts a tweet, ships it, and only then do you find out. The brand takes the hit, and you spend the afternoon deleting. No founder lives with that twice.
An agent that asks forty times a day. Every tiny step comes back as a "should I?" and the thread is noise. You stop reading, then you approve blindly to make it stop. The safety that was meant to protect you trains you to ignore it.
Both are approval failures. The first has too little gate, the second has too much, and neither actually asks the question that matters.
The question the docs never ask
The tutorials all ask whether there should be approval at all. Full auto or approve everything, pick one.
That is the wrong question. An AI agent will not only do one thing. It drafts, researches, audits, plans, and occasionally publishes. Running all of those through the same yes/no is how you end up at one of the two failure modes.
The right question is: where does approval live, and how often do you have to give it? An approval queue in a dashboard you open once a week is not a safety loop, it is a delay. The gate only works if you actually see it, and you actually see what is in front of you.
Slack is the approval surface
Put the approval where you already live: Slack, not another dashboard you will stop opening.
Reply once, from the channel you are already in. Approve, edit, or deny without switching tools. The agent posts the candidate, you type a word, and the change ships or does not. That is step three of the loop: "you approve, from Slack."
What to gate, what to delegate
Not everything in the loop deserves the same treatment. A clean split:
| Action | Wait for your yes? |
|---|---|
| Publish a blog post | Yes |
| Post to X or LinkedIn | Yes |
| Send outbound | Yes |
| Spend money | Yes |
| Draft a post | No |
| Research a topic | No |
| Audit a page | No |
| Plan a sprint | No |
The reversible things never ask, because asking about them is the noise that trains you to approve blindly. The irreversible things always wait, because that is the gate that keeps you safe. "You approve everything" sounds reassuring and is a bug: it buries the one thing you actually care about under forty you do not.
Standing permissions: the third option
Full auto and approve-everything are not the only two choices. There is a third: standing permissions.
Tell Marlo it can decide this class of thing on its own from now on, and it will. Approve the same kind of post twice, and the third one does not ask. You make the call once, explicitly, and the agent stops asking for it.
These are grants you make, not defaults. You never hand the agent a blank check by accident. But you also stop re-answering the question you already answered.
What remembering changes
Give it a few weeks and the texture of the loop changes. The question count shrinks. The same human gate stays on publishing, sending, and spending, the parts you would never delegate. The approvals that protected you are still there.
What goes away is the noise. That is the entire point of standing permissions: fewer questions over time, more shipped, same gate on the scary stuff. The approval stays, the noise goes.
This post is a pull request, in Slack, waiting
We run our own marketing loop on the pattern this page describes. Drafts and edits arrive as pull requests; publishing waits for a human yes. Meet the agents behind it, and start free to see the first batch waiting in your Slack channel.