The Missing Approval Step: Auditing an AI-Drafted Reply Workflow
Objective: Given a workflow diagram where an LLM node drafts a customer reply, decide at which points a human approval step is missing, applying the lesson's guardrails for cost, latency, and trust before recommending a fix.
You're auditing an automation built by a well-meaning ops intern at Walker & Company Brands (Bevel), the grooming-products company acquired by P&G. The workflow drafts and auto-sends replies to demo requests with zero human review.
Read the workflow diagram, decide where the missing approval step is, and write the guardrail that fixes it, citing the lesson's rule about what must never send without a human.
Before you start
What you'll need
Free path (everything below is enough to finish)
Free self-hosted tier, full access to the visual node editor needed to trace and fix the workflow
The process
2 steps
Step 01 of 02
The lesson's guardrail is explicit: keep a human approval step on anything that sends, publishes, or routes to a person outside your team, at least until accuracy is verified on 50+ real runs.
The diagram shows: form submitted -> LLM drafts a reply -> reply auto-sends via email, no approval node anywhere. Where does the fix go, and what does it change?
Procedure
- Trace the path from trigger to the email-send action
- Identify that no node between the LLM draft and the send action requires a human click
- Insert an approval node (Slack message with Approve/Edit buttons) between draft and send
- Route 'Edit' back to a human-editable draft, not straight to send
AUDIT FINDING Gap: LLM draft node connects directly to email-send action, 0 human touchpoints. Fix: Insert Slack approval node between draft and send. Approve -> send. Edit -> human-editable draft -> send.
Healthy
Every AI-drafted external send has at least one human click between draft and send.
Unhealthy
An AI-drafted reply reaches a real customer's inbox with zero human review.
What this means
The lesson's own worked example 3 (personalized follow-up) posts drafts to a Slack approval channel for exactly this reason, the AI writes, a human still owns the send button.
So what do I do about it?
| Symptom | Action | Effort |
|---|---|---|
| Customers receive AI-drafted replies with no human review | Insert a Slack or email approval node before any external send action | 30 min |
Step 02 of 02
The lesson warns against putting an LLM step in front of every automation by default, reserve the AI step for decisions a rule genuinely cannot make.
The same workflow also runs an LLM check on whether the 'company name' field is blank before proceeding. Is that a good use of the LLM node?
Procedure
- Locate the LLM node checking for a blank field
- Confirm a one-line conditional filter (IF company_name is empty) can do the same check for free
- Replace the LLM node with a hardcoded filter node
- Keep the LLM node only for the actual drafting step further down the chain
AUDIT FINDING LLM node #1 (blank-field check): replace with IF filter, saves 1 API call per run, 1-4 sec of latency. LLM node #2 (reply drafting): keep, this genuinely needs judgment.
Healthy
LLM nodes are reserved for judgment calls; simple presence/absence checks use free conditional filters.
Unhealthy
An LLM call runs on every single form submission just to check if a field is empty.
What this means
Paying latency and cost for something a one-line filter already does for free adds up at volume with no benefit.
So what do I do about it?
| Symptom | Action | Effort |
|---|---|---|
| Workflow runs slower and costs more than a comparable rule-based version | Replace any LLM node doing a check a hardcoded filter could do | 5 min |
Final deliverable
A written audit report listing every missing approval gate and every misused LLM node, with the exact fix for each.
See a reference example
Halo Top, demo-request workflow audit FINDING 1 (critical): LLM-drafted reply auto-sends with zero approval step. Fix: Insert Slack approval node (Approve/Edit) between draft and send. FINDING 2 (cost/latency): LLM node checks for blank 'company' field. Fix: Replace with a free IF filter, no API call needed. FINDING 3 (clean): LLM node classifying reply intent (interested/not-now/hard-no) is a genuine judgment call, correctly implemented.
Success criteria
You're done when you can:
- Correctly flags the missing approval step before any external send
- Correctly distinguishes a genuine judgment call from a check a filter could do for free