Answers
How do I make an AI agent ask a person before it acts?
Route each consequential action through a decision that can answer "a person decides". Immiscible holds the request, asks the named person in the console, by email, in Slack or in Teams, and tells the agent once they have decided.
Send each consequential action (a payment, a data release, an email, a tool call that reaches another system) to a decision point before it runs, and let that decision answer “a person decides”. With Immiscible the answer is approval_required: the agent waits, the person gets the request in the console, by email, or in Slack or Teams with Approve and Deny in the message, and the agent polls until it becomes allow or deny.
#How do I set it up?
- Connect the agent:
npx immiscible initwrites its key to.env. See the CLI. - Write the rule. Rules say what an agent may do alone and when it must ask: above an amount, at a new merchant, before personal data leaves, before a tool reaches a domain not on its list. A new agent asks about everything that matters until it has earned more (autonomy tiers).
- Guard the action. The SDK asks, waits for the person, and runs your function only on allow:
import { Immiscible, toolAction } from '@immiscible/sdk';
const immiscible = new Immiscible().run();
await immiscible.guard(toolAction('send_email', { to: 'client@acme.example' }, { domain: 'acme.example' }), () => sendEmail());from immiscible import Immiscible, tool_action
run = Immiscible().run()
with run.guard(tool_action("send_email", {"to": "client@acme.example"}, domain="acme.example")):
send_email()Or over plain HTTP: POST /v1/actions/authorize, then poll GET /v1/actions/:id. The contract is on for AI agents.
#Can approvals happen in Slack or Microsoft Teams?
Yes. Requests reach the approver in Slack or Teams with Approve and Deny in the message, and a decision there is the console’s decision with every rule the console applies. Above a line you set, chat refuses to approve and sends the person to the console, where their own sign-in and two-factor stand behind the click. See approvals in Slack and Teams.
#Is there an MCP server for approvals?
Yes: https://immiscible.fly.dev/mcp. Its tools request_payment, request_personal_data and authorize_action ask before acting, check_action_status polls while a person decides, and explain_decision says why in plain English. Add it with one command; see add the MCP server.
#What does the agent do while it waits?
Nothing consequential. It tells the person it acts for, with the approval link, and polls every five seconds for a minute, then every thirty. Retries use the same idempotency key, so a person is never asked twice for the same thing. A request nobody answers does not become an allow.
#What does it not do?
- When the agent is the only one asking, asking is its choice. Pair it with a gate it cannot route around: the Claude Code hook, the MCP proxy or the card rail.
- It does not judge whether the work was good; it decides whether the action may happen, and records it.
For framework-specific wiring, see approvals in the OpenAI Agents SDK, LangGraph and the Vercel AI SDK.