Nobody reads the four hundredth approval

August 11, 2026

Nobody reads the four hundredth approval

There is now a named attack technique that targets the person clicking approve. If your AI review queue never shrinks, you bought payroll, not oversight.

Last week a security blog put a name to something support teams have been living with all year. On August 5, WorkOS published a piece on approval fatigue and noted that an open threat-detection ruleset had added an entry in March 2026 called “Human Approval Fatigue Exploitation.” The pattern: an attacker gets an agent to fire off rapid repeated permission requests, wraps a dangerous action in minimizing language so it reads as routine, or buries one risky operation inside a batch of harmless ones.

Read that twice. There is now a catalogued attack technique whose target is not the model and not the API. It is the person clicking approve.

The loop we sold as the fix

Every agent incident for the past two years has been answered with the same sentence. Keep a human in the loop. It sounds unarguable, and it survived because nobody looked closely at what the loop turned into.

It turned into a queue. Every action the agent is not trusted to take alone becomes a row somebody has to read and click. That design quietly moves your entire safety margin onto one line item nobody costed: a single person’s attention, late in the day, with the rest of their job still waiting.

Data & Society’s Ranjit Singh and Samir Passi call this the oversight fallacy. Approval prompts and pause buttons only work when the person can recognize a mistake and intervene before the consequences cascade. In support, that condition fails without anyone noticing. The reviewer sees a proposed reply. They do not see the twelve retrieved facts underneath it, or the balance the agent read off the wrong account, or the policy that changed in March.

The pause button is in worse shape than the prompt. Kiteworks’ 2026 forecast found 60 percent of organizations cannot terminate a misbehaving AI agent at all. The Cloud Security Alliance reported in April that 65 percent had already had a security incident caused by one.

Support is the exact shape that breaks human review

Support queues have a specific profile. Huge volume, almost all of it individually trivial, and then with no warning one item where the stakes are real. The refund that is twelve thousand dollars instead of fifty. The cancellation on the account paying for a quarter of your month. The sentence that is legally a promise.

That is close to the worst possible input to human review. Four hundred approvals in a row are fine, and that teaches your reviewer something true: approving is safe. Human factors research has said the same thing for decades. When a system is usually right, people stop verifying and the click becomes a reflex, while the audit log keeps faithfully recording a human decision. The paperwork says oversight. The behavior is a rubber stamp.

Attackers worked this out too. That is why the technique has a name now.

One question to ask a vendor

Six months in, will my review queue be smaller than it was in week one?

If the answer is no, that is not governance. That is payroll with an audit trail. A review queue that never shrinks is a system admitting it never learned which decisions were safe, and never earned the right to make any of them.

Oversight that holds up has to do two things a queue cannot do by itself.

Spend the human’s attention only where there is real doubt. Checking work the agent already gets right nine hundred times out of a thousand makes nobody safer. It just makes the reviewer numb for the one that mattered.

Then put the hard limits somewhere the human never has to notice. Product leader Nixal Patel made the point plainly on August 10, writing about agent authority versus agent capability: “Deny must be enforced outside the system prompt.” If a refund over your ceiling depends on somebody spotting it in a list, you do not have a ceiling. You have a hope.

Why we build around graduation instead

Celeste practices before it has any authority. It drafts on your real tickets with nothing reaching a customer, and each draft sits next to the reply your team actually sent. You watch it get close on your own traffic, at volume, where a wrong answer costs nothing. That comparison is the review, and it happens before a customer is on the other end of it.

Then topics move up one at a time. Co-pilot, where a person sends. Autonomous, where the agent sends inside limits you set. Anything you have not graduated stays in practice. The queue you actually read stays short on purpose, because it only ever holds the cases you are still making up your mind about. One click drops a topic back to watching.

And the limits are not requests. The model proposes an action, and deterministic code decides whether it runs. A refund past your ceiling does not get flagged for review at the bottom of a long list. It does not go.

The industry has spent two years arguing about how much autonomy to hand an AI agent. The more useful question is who does the deciding, and whether that answer still holds at 5pm on a Friday with four hundred rows in the queue.

More from the blog Live Admin Demo