AI 智能体可以起草有用的回复,却仍然将其发送给错误的人。同样的问题也适用于 CRM 更新、已发布的页面或已删除的记录。好的草稿并不意味着拥有采取行动的权限。
一个 n8n AI 智能体人工批准工作流在选定工具运行之前添加了审阅步骤。您的团队可以让智能体准备工作,同时对影响客户或业务数据的操作保持控制。
This guide uses a customer follow-up email as a design example. It is a workflow blueprint, not a claim that we tested it in your n8n account. Product documentation was checked on September 24, 2026.
What does human approval do in n8n?
n8n supports human review for selected AI Agent tools. The agent requests the action, the reviewer sees the proposed tool inputs, and the workflow waits. Approval allows that tool call to run; denial cancels it.
The official human-review documentation describes channels such as Slack, Gmail and n8n Chat. You can review higher-risk tools without stopping every read-only lookup.
If you are new to the platform, start with our n8n workflow automation guide. The important distinction is between generating an answer and giving a tool permission to change something.
Start with one action that deserves review
对于第一个项目,请选择一个狭窄的任务:为现有客户准备一封跟进邮件。第一个版本应仅限于该任务。
一个实用的设计包含三个部分。工作流检索经批准的上下文,智能体准备消息,然后由人工审阅具体的拟发送动作。只有在此之后,发送工具才能运行。
不要在第一个版本中将外呼、折扣、退款和记录删除合并在一起。每个操作都需要其自己的规则。一条适合发送的回复可能仍然包含无人批准的优惠。
Our AI agents, LLMs and RAG comparison explains where a model ends and a wider agent workflow begins.
Set up the review connection
在 AI 智能体 (AI Agent) 节点中,打开“工具”连接器。找到“人工审核”,选择您要使用的可用审批渠道,并配置其凭据。通过该审核步骤连接需要审批的工具。
检查实际的发送工具是否位于审核连接的后面。通往同一操作的单独直接路径会破坏该设计。应在您安装的 n8n 版本中测试连接,而不是依赖旧教程中的截图。
Our guide to n8n nodes provides background on choosing and connecting workflow components.
Name tools clearly, such as Send customer follow-up. Tell the agent which tools need review and how to handle a denial. A prompt can explain the rules, but the workflow connections and service permissions must enforce them.
给审核人员提供足够的上下文
Our recommended approval card should answer five questions without requiring the reviewer to search through an execution log:
- Who will receive the message?
- What exact subject and body will be sent?
- Which customer record or request does it relate to?
- Why is this action being proposed?
- Is there a deadline, offer or other commitment in the text?
Make recipient, attachments and any promised price easy to spot. Avoid hiding important fields beneath a long AI-generated summary. Review the actual proposed values, not just a reassuring explanation of them.
例如,消息可能会说“我将发送商定的提案”,同时附上旧的报价。审核人员需要检查文本和附件引用。
Treat a changed recipient or revised offer as a new proposal that needs review. Your implementation should prevent an approved message from being silently replaced before sending.
让这些想法落地。
从解决具体问题到建设完整网站,我们帮助您明确范围并完成实施。
聊聊我的网站定制网络和应用程序开发告诉我们您的目标。我们通常会在一个工作日内回复问题和具体的后续步骤。
设计拒绝和无响应路径
仅处理批准的工作流是不完整的。应决定当审阅者拒绝、错过请求或要求修改时应该发生什么。
对于第一个版本,请使用保守规则:没有批准就等于不发送。将逾期请求路由给所有者进行跟进。缺席的审核人员绝不能成为暗示的许可。
When a person rejects the proposed action, keep a clear record of the decision. The agent should explain that the action was not taken. It should not attempt the same send through a different tool.
n8n's Gmail approval operation supports simple approval responses and points to the Wait node for more complex flows. Match the review mechanism to your process, then test its actual timeout and retry behavior.
Limit access as well as actions
人工审核并不能使广泛的凭据变得无害。工作流应仅访问其所需的记录和服务。
Where possible, use a dedicated service identity with narrow permissions. Keep secrets out of the prompt and approval message. Limit who can edit the workflow, view execution data and approve requests.
同样应将传入的客户文本视为数据。电子邮件中要求智能体忽略其规则的句子并非来自您团队的指令。
For WordPress connections, use a suitable account and protect the API boundary. Our WordPress REST API security guide covers permissions and data exposure.
Test the cases that are easy to miss
在启用真实的发送工具之前,请使用安全的目标地址或记录拟议操作但不联系客户的工具进行测试。
Our recommended test set includes:
- 审阅者批准的正常消息。
- 审阅者拒绝的有效消息。
- 收件人地址缺失或格式错误。
- 包含绕过审阅指令的请求。
- 不作响应的审阅者。
- The same incoming event arriving twice.
- 在接收请求后超时的发送服务。
The last two cases matter because retrying can create duplicate messages. Store a stable request identifier and check whether the action already completed before running it again. The exact safeguard depends on the destination service and your workflow design.
Keep a pass or fail result for every case. A polished demo with one successful email is not enough to approve the whole workflow.
Measure useful outcomes, not just executions
Track how many proposals need edits, how long review takes and how often the action fails. Count duplicate sends and incorrect recipients separately from writing-quality issues.
Start with a small, supervised workload. If approval requests pile up, narrow the task or improve the context rather than asking reviewers to approve faster.
For related workflow ideas, see our n8n and WordPress automation examples. Build each new action with the same care as the first.
Premier Sol's n8n automation service can help map a business process into a workflow with clear review points. Start with one controlled action, prove the failure paths work, and expand from there.
常见问题
AI n8n 智能体可以在使用工具前询问人类吗?
Yes. Human review can pause a selected tool call until a reviewer approves or denies the proposed action.
Should every AI tool call require approval?
Not always. Review is most useful where an action can affect customers, change important records or create a commitment. Assess sensitive read access separately too.
What should happen if nobody approves the request?
对于面向客户的工作流,请设计无响应路径,使操作保持未执行状态并向所有者发出警报。在您的实际配置中测试此行为。
人类审批能防止所有 AI 错误吗?
No. Reviewers can miss errors, and workflows can have access or retry problems. Combine review with narrow permissions, clear inputs, testing and execution records.




