Where the line is: what an AI agent may decide and what you approve

An agent that asks you about everything saves no time. An agent that asks nothing can break a lot. The line comes down to one simple question: can it be undone?
New to this topic? Start with What Are Agentic Workflows? A Practical Guide for Teams
Every agent's dilemma
An AI agent is useful because it takes steps on its own. You give a goal, and it decides which actions are needed: reading mail, looking something up, making an overview, writing a draft.
But how independent do you want that to be? An agent that asks permission for every step is a complicated way of doing it yourself. An agent that never asks anything might send a wrong email to your best customer.
You do not solve that dilemma with trust or distrust. You solve it with a clear line.
The line: can it be undone?
The most useful question is not "how important is this?", but "can I undo this?".
| Kind of action | Example | Can it be undone? | Who decides |
|---|---|---|---|
| Reading | Summarising the inbox, checking the calendar, reading a document | Nothing changes | The agent |
| Preparing | Writing a draft, making an overview, drawing up a proposal | Something is ready, nothing has been sent | The agent |
| Changing | Creating a calendar item, moving a deal, updating a row | Usually, with some effort | You, after a proposal |
| Sending or publishing | Sending an email, posting, putting an article live | No | You, always |
Reading and preparing cannot break anything, so an agent may move freely there. The further down that table an action sits, the more important your approval becomes.
Reading is always allowed, changing asks for approval
In dGENIX this is the pattern that runs through the whole platform. GENI reads your context, chooses which skills it needs, fetches data and summarises. As soon as a step changes or sends something, it proposes it and waits.
Take an instruction like:
"Summarise my unread mail and put the action points in my calendar."
What happens then:
- GENI reads your context and chooses the skills: Gmail and Google Calendar.
- It checks whether those connections exist. If not, it says so.
- It fetches your mail and summarises.
- It proposes the calendar items and asks for confirmation, because that changes something.
- After your approval, it carries it out.
Step three it does itself. Step four waits for you. That is the line in practice.
Why scheduled tasks too
You would think a scheduled task is meant to run without you. That is true for the reading work. But in dGENIX, irreversible actions ask for confirmation even inside a scheduled task.
The result: a task that prepares review requests or follow-up emails every Monday runs entirely on its own up to the moment of sending. Then everything is ready and you approve it. No email or publication ever goes out unseen.
That costs you a minute a week. It saves you the one time something went wrong without you knowing.
Money is irreversible too
There is a second kind of action that asks for approval: something that costs a lot. A heavy audit, a series of images, a big campaign. For those, GENI says up front what it costs and asks whether it may continue.
Some limits are also fixed rules. A review campaign to more than twenty-five recipients always asks for confirmation, even when it is scheduled. If a paid action fails, the credits come back.
What an agent never does
Besides approval, there are actions an agent in dGENIX does not carry out at all, not even if you ask:
- Deleting. GENI does not erase mail, files, contacts or deals.
- Publishing without you. Content for your website goes into your CMS as a draft; you press publish.
- Taking access you did not give. Without a connection it gets nowhere.
Those are not temporary limitations. An assistant that can erase your saved work itself is an assistant you have to check every week.
How to move the line for yourself
The line is a starting point, not a law. As you see a task run more often, you learn how reliable it is. Then you can consciously choose how much you let it prepare:
- Start with reading. A daily overview of mail and calendar. Watch for a few weeks how good it is.
- Move to preparing. Have draft replies prepared. You adjust them and send them yourself.
- Let it make proposals. After a conversation, let GENI propose what should go into the CRM. You approve.
Which task to tackle first is covered in which task to automate first.
Proactive, but with your approval
A step further is an agent that comes up with ideas itself. In dGENIX you can switch on Proactive GENI. GENI then thinks along with you once a day based on what you did, and puts suggested follow-up tasks in your Workspace. It is off by default, and you approve every suggested task yourself.
That way you get the benefit of an agent that thinks ahead, without it deciding for you.
Where it comes together
The engines follow the same line. The Authority Engine writes articles and puts them in your CMS as drafts, with a preview and the option to roll back. The Reputation Engine prepares review requests and asks for confirmation for larger numbers.
What an agentic workflow exactly is, is covered in what are agentic workflows. The difference with a chatbot that only answers, you can read in agentic AI vs chatbots.
Frequently asked questions
Can I turn off the confirmation?
Not for irreversible actions such as sending and publishing. That is a deliberate choice. Reading and preparing need no confirmation, so you do not notice it there.
What if I miss the confirmation for a scheduled task?
Then the action waits until you look at it. Nothing goes out without your approval. Have the task email the result or send it to Telegram, so you see it sooner.
Does GENI decide which skills it uses?
Yes, and that is reading and preparing. You do not need to name a skill. If you want to steer anyway, you can by naming it in your instruction.


