Learn

Human Approval in AI Workflows: What to Check Before Buying

An approval step protects you only if it pauses before the action, knows who approved, handles decline and silence, and is on your plan. Compare Zapier, n8n and Make with an approval-state matrix and a synthetic credit-note example.

Start with the selection criteria. Use this page when you know the category and need a practical framework for narrowing the field.

UpdatedOctober 2, 2026
Browse tool profiles

Editorial guide

Guide

Start with the criteria, tradeoffs, and shortlist logic before you open individual tools.

Short answer: an approval step only protects you if it does four things:

  • it pauses before the action;
  • it knows who approved;
  • it has a defined path for decline and silence;
  • it is included in the plan you are buying.

The three platforms differ most on those points:

  • Zapier has a built-in Human in the Loop step on paid plans. On Professional you can only send approval requests to yourself, so approval by colleagues needs Team or Enterprise.
  • n8n builds approvals into its messaging nodes ("send and wait") and into AI agent tools. Its default email-style link buttons cannot tell who clicked, so verified approver identity needs a channel that checks it, such as Slack approvals with Capture Who Responded turned on.
  • Make offers a Human in the Loop app only on Enterprise, as a closed beta. On other plans you build the approval yourself from webhooks and stored state, and instructions to an AI agent are not an enforced gate.

Ask every vendor to demonstrate the decline, timeout and wrong-person cases before you buy, not only the happy path.

Approval before the action vs review after it

These are different controls, and buyers often get one when they meant to buy the other.

  • Approval before the action pauses the run. Nothing is sent, paid, deleted or published until a named person says yes. Use it for irreversible or customer-facing actions.
  • Review after the fact lets the run finish and gives someone a log, a report or a sample to check later. Use it for low-risk, high-volume work where mistakes are cheap to correct.

A run history, an audit log or a weekly report is review after the fact. Only a pause that the platform enforces is approval before the action. A prompt that tells an AI to "check with a human first" is neither, because the model can ignore it.

The approval-state matrix

Every approval step can end in more states than "approved". Decide in advance what each state does, then check that the platform can express it.

State

What should happen

Zapier Human in the Loop

n8n

Make (self-built on non-Enterprise plans)

Pending

Nothing changes; the item is visible to the approver and the requester

The Zap pauses at the Request Approval step; reminders can be scheduled

Send-and-wait nodes and the Wait node pause the execution and store its data

A data-store record marked "pending" with an ID and an expiry time

Approved

The action runs once, with the approved values

The run continues

The run continues

A webhook scenario checks that the record is still pending, then runs the action

Approved with edits

The action uses the edited values, and the edit is logged

Reviewers can edit content when you allow it; edits arrive as separate "Edited Content" fields you must map

Approval buttons return approve or decline; to accept edited values, resume a Wait node through its webhook with the new values and map them in the next step

Pass the edited values in the webhook call or a form

Declined

The action does not run; the requester is told why

Action if reviewer declines can be Continue run or Stop run. Choose deliberately, and branch on the decision if the run continues

With Approve and Disapprove you get both buttons; Gmail's Send and Wait for Approval defaults to Approve Only, so add the decline option

Mark the record declined; a second click on Approve must then do nothing

Timed out

A named owner is told; the action does not run by default

On timeout: Skip and continue or End run, after a timeout in minutes, hours, days or weeks

The Wait node's Limit Wait Time resumes after a set interval or date; add a check after it so a resume without a decision goes to a "no decision" path

A scheduled scenario expires stale records and alerts the owner

Wrong person responds

The response is rejected and the item stays pending

Reviewers must have a Zapier account and access to the Zap. On Team and Enterprise, Specific members of my account requires them to log in as one of the selected users; an Anyone reviewer type also exists, so test its access rules

Default link buttons accept anyone with the link. Slack approvals with Capture Who Responded on can restrict approvers and record who responded; with an empty approver list, anyone who can see the message can respond

A plain link cannot identify who clicked; require login or a signed, single-use link you build

Clicked twice

The first decision stands

Only one user can complete a review

With link buttons, the first decision stands and later clicks see a "no action required" page

Check the record's state before acting

Action fails after approval

The approval is not reused silently; someone decides whether to retry

Replays and autoreplay re-run errored steps; in some configurations Human in the Loop steps do not autoreplay

Retry the execution from the executions list, and check which steps re-run

Incomplete executions (if enabled) keep the failed run for retry

The decline row is the one most often missed. On Zapier, a decline that continues the run will still reach later steps unless you add a branch. On n8n, the Gmail approval node shows only an Approve button unless you change the type.

Who can approve, and on which plan

Question

Zapier

n8n

Make

Built-in approval step

Human in the Loop on Professional, Team and Enterprise (not Free)

Send-and-wait operations on messaging nodes such as Gmail and Slack; human review for AI Agent tools; the Wait node for custom flows

Human in the Loop app on Enterprise only, in closed beta

Approving someone else's run

Professional: requests go only to yourself. Team and Enterprise: named users in the account, or the Anyone reviewer type for people outside it (they still need a Zapier account)

Anyone you send the request to; identity is verified only on channels that check it, such as Slack approvals with a restricted approver list

Whatever your own build enforces

Approver needs an account

Yes, a Zapier account with access to the Zap

Not for link buttons; Slack approvals need a Slack app with Interactivity and its signing secret, and a Slack user on the approver list

Depends on your build

AI tool calls

Require approval before running per tool in AI by Zapier; off by default

Human review per tool on the AI Agent; reviewers approve or deny, and a denial is reported back to the agent

Make's AI agent guidance suggests adding a review tool and instructing the agent to use it; the platform does not enforce it

Limits to know

Not available within or after a Looping step; successful approvals count as tasks

Slack approvals need the instance reachable from Slack over public HTTPS

Your build must handle expiry, identity and double clicks

Zapier Team starts at $69 a month billed annually ($103.50 monthly) for 2,000 tasks and up to 25 users. n8n Cloud starts at €20 a month billed annually for 2,500 executions. Make Core starts at $12 a month billed annually ($16 monthly) for 10,000 credits, but its built-in approval app is Enterprise-only. See Zapier pricing, n8n pricing and Make pricing.

Worked example: approving a customer credit note

Everything below is invented. "Example Co" lets an automation draft credit notes, but any credit above $500 needs approval from the finance lead, Dana, within one business day.

  1. Draft. The workflow creates a draft credit note in the billing system and stores its ID. Nothing is issued yet.
  2. Request. It sends Dana an approval request showing the customer, the amount, the reason and a link to the draft.
  3. Wait. The run pauses until the end of the next business day (set as a fixed timeout or a computed date), with a reminder halfway.
  4. Decide. Each outcome has its own path:
  • Approved: the workflow issues the credit note and logs Dana's name and the time.
  • Approved with a lower amount: it updates the draft to the edited amount, then issues it.
  • Declined: it deletes the draft, records Dana's note, and tells the account manager.
  • No answer: it leaves the draft unissued and alerts the deputy approver.
  • Someone else clicks: the response is refused and the request stays pending.
  1. Act once. Before issuing, the workflow checks that the draft still exists and has not already been issued, so a replay cannot issue it twice.

How this maps to each platform:

  • Zapier: use Team so Dana can be a named reviewer. Set Action if reviewer declines to Stop run, or branch on the decision. Set On timeout to End run and alert on ended runs.
  • n8n: send the request through Slack's Send and Wait for Response with Capture Who Responded on and Dana as the only approver, and wrap the wait with Limit Wait Time. Gmail's Send and Wait (set to Approve and Disapprove) cannot refuse a click from someone else, so use it only if a forwarded link is an acceptable risk.
  • Make: on Enterprise, ask for access to the Human in the Loop beta. Otherwise build two scenarios (request and decision), a data-store record with an expiry, and a scheduled clean-up.

Questions to ask in a demo

  • Show a decline. What runs next, and can a later step still act?
  • Show a timeout. Where does the item go, and who is told?
  • Have someone who is not the approver open the request. Is the response refused?
  • Approve, then make the next step fail. What does a replay re-run, and could it act twice?
  • Where is the approver's name and decision stored, and for how long?
  • Which plan includes each of these, and what does each approval cost in tasks, executions or credits?

Who should not rely on built-in approval steps

  • Processes with legal sign-off requirements, such as contract signature or regulated payment release. Use the system of record's own approval controls and keep the automation to drafting.
  • Teams without a named approver and deputy. A pending queue nobody watches turns every timeout into an outage.
  • Very high volumes. If people approve hundreds of items a day, approvals become rubber stamps. Narrow the gate to high-risk items and review the rest after the fact.

For approval patterns specific to outbound email, see AI email triage. For escalation in support queues, see AI support ticket routing and escalation.

Evidence boundary

Official sources

Editorial guidance grounded in official product sources.

FAQ

Common questions

Where is the approval decision recorded, and for how long?

On Zapier, the decision, any edited content and the reviewer note appear in the step results in Zap history, which is kept 29 to 69 days, and Human in the Loop activity appears in the audit log. On n8n, Slack approvals with Capture Who Responded put the responder's details in the node output, which lasts as long as execution data is kept. A self-built Make approval lasts as long as your data store keeps the record. Copy decisions you must keep longer into your own system.

Can someone outside our Zapier account approve a request?

Zapier documents an Anyone reviewer type for people outside your account, but each reviewer still needs a Zapier account (they are prompted to create one), and the same article says the Zap must be shared with reviewers. On Professional, requests go only to yourself. If identity matters, use Specific members of my account on Team or Enterprise, and test what an outside reviewer sees before relying on it.

Does each approval use tasks, executions or credits?

On Zapier, only successful Human in the Loop actions count as tasks; previews and notifications do not. On n8n Cloud, billing is per workflow execution, so confirm in a trial how a paused and resumed run is counted. On Make, a self-built approval splits into a request scenario and a decision scenario, and each one consumes credits for its modules.

Can an AI agent approve its own tool calls?

It should not. Approval needs to go to a person through the platform: per-tool approval in AI by Zapier or human review on n8n agent tools. Make's AI agent guidance relies on instructing the agent to send work to a reviewer, which the platform does not enforce.

How long should a run wait for approval?

Set a business deadline rather than relying on platform maximums, add a reminder, and name a deputy for timeouts. Zapier lets you set the timeout in minutes, hours, days or weeks, with Skip and continue or End run when it expires. n8n's Wait node can resume after a time limit, and that branch should go to a no-decision path.

Next steps

Take the next evaluation step

Use these next pages to evaluate the strongest candidates, supporting profiles, or follow-up guides against the selection criteria.

View all tools