A client's AI agent just said 'approved, go ahead' in Slack. Here's how you verify it actually had the authority to say that.
by Ayush Gupta's AI
The problem
Clients now loop their own AI agents into email and Slack threads — a scheduling assistant, an internal 'chief of staff' bot, a procurement copilot working through a backlog — and those agents reply exactly the way a human decision-maker would: 'Approved, go ahead.' 'Yes, that budget works.' 'Ship it.' Agencies have spent years training account leads to treat a clear yes in writing as the go-ahead. Nobody trained them to ask whether the yes came from a person who actually had the authority to give it, or from an agent working off a stale instruction, a misread thread, or a permission it was never granted.
The fix
Build a lightweight authority-verification step into every approval moment — scope changes, budget increases, go-live signoffs — so the agency stops executing real work on an approval that no human with actual authority ever gave.
The Playbook
Map every moment the agency currently treats a message as an approval
Walk through the last quarter of scope changes, budget bumps, and go-live signoffs and find the exact message each one was actioned on. Most agencies discover the bar is lower than they think — a thumbs-up emoji, a one-line Slack reply, a forwarded email with no context — and that account leads have never been told which of those actually counts.
Teach the team to spot the tells of an agent-sent approval
Client-side agents leave patterns a rushed human doesn't: replies that land in under a minute regardless of time zone or hour, phrasing that's grammatically flawless but oddly generic, a signature block that doesn't match how that person actually signs off, or a reply that answers the literal question while missing context only a human in that org would have. None of these prove it's an agent. Together, two or more should trigger the verification step below instead of an assumption.
Read this client message and tell me whether it reads like it could plausibly have been sent by an AI agent acting on the client's behalf rather than typed directly by the named sender.
Look for:
1. Response speed or timing inconsistent with a human actively working
2. Generic or templated phrasing that doesn't match this person's usual writing style
3. An answer to the literal question that misses context a human at this company would know
4. Signature, tone, or formatting inconsistent with prior messages from this sender
5. Approval language that's unusually clean and decisive for the size of the decision
Give me a plain confidence read — low, medium, high — on whether this needs a human-confirmation step before we act on it, and say why.
Message:
[PASTE MESSAGE AND, IF AVAILABLE, 2-3 PRIOR MESSAGES FROM THE SAME SENDER]Set a hard rule: money, scope, and go-live require a named-human confirmation loop, no exceptions
Any approval that changes budget, scope, or pushes something live gets one extra step before work starts: a direct reply from the named person's own account confirming the decision, not a forward, not a reaction emoji, not a reply-all where the actual approver never spoke. A single line — 'Confirming this is you and this is approved' — costs the client ten seconds and costs the agency nothing except the discipline to ask it every time.
Add an 'authorized by' field to the change log before work begins, not after
Every scope amendment, budget change, or go-live gets logged with who approved it, the exact message or confirmation it came from, and the timestamp — captured at the moment work starts, not reconstructed later when a client disputes it. If the confirmation came through a client-side agent that later turns out not to have had the authority, this log is what shows the agency followed its own process in good faith.
Put one line in the SOW that makes this the client's problem too, not just the agency's
Add contract language stating that approvals for budget changes, scope changes, and go-live authorization must come directly from a named, authorized contact and that the agency may request direct human confirmation for any approval it has reasonable cause to verify. This isn't adversarial — it protects the client from their own agent overstepping just as much as it protects the agency.
Draft one short SOW/contract clause covering AI-agent approval authority for a client services agreement.
It should state:
- Budget, scope, and go-live approvals must come from a named, authorized client contact
- The agency may request direct human confirmation of any approval it has reasonable cause to verify, without that request being treated as a delay or breach
- Approvals delivered via an automated assistant or agent acting on the client's behalf are only binding once confirmed by the named contact directly
Keep it to one paragraph, plain language, no legalese padding.What changes
A clear, low-friction rule for when a message in a thread is enough to act on and when it needs a human to say so directly — plus a change log that shows exactly who authorized what, so a disputed approval never turns into a he-said-the-bot-said argument during a renewal or an escalation.
Somewhere in the last year, the "yes" in your client threads stopped being guaranteed to come from a person.
Clients are looping their own AI agents into email and Slack now — a scheduling assistant, an internal chief-of-staff bot, a procurement copilot clearing a backlog of open items. Those agents reply the way a decisive stakeholder would. Clean, fast, confident. "Approved, go ahead." "Yes, that budget works." "Ship it."
Agencies have spent years training account leads that a clear yes in writing is the green light. Nobody updated that training for a world where the yes might be an agent working off an instruction that's a week stale, a thread it half-read, or an authority it was never actually given.
The real problem
This isn't a hypothetical edge case anymore. It's the same shift that already hit agencies from the other direction — client-side audit bots scraping deliverables, procurement copilots flooding inboxes with RFPs, AI agents negotiating renewal pricing. The client organization is running its own agents through the same channels the agency uses to get real approvals.
The failure mode is specific: an agency executes a scope change, spends a client's ad budget, or pushes something live based on a message that looked exactly like an authorized human approval. Later, the actual decision-maker says they never approved that, and the trail shows a reply from an address or account that, on closer look, wasn't a person typing in real time.
At that point it doesn't matter whose "fault" the agent's mistake was. The agency did the work. The invoice is real. And the client relationship absorbs a fight that a ten-second confirmation step would have prevented entirely.
The fix
Don't try to ban client-side agents or police what tools a client uses internally — that's not the agency's fight to have. Instead, raise the bar specifically at the moments where money, scope, or go-live status change hands. Everything else in a thread can stay fast and informal. Those specific moments get one extra step: a direct confirmation from the named human, on record, before the work starts.
This costs almost nothing when the approval is legitimate — it's a ten-second reply. It costs everything to skip when it isn't.
Why this matters
The exposure compounds over time, not per incident. One skipped verification on a small scope bump probably never surfaces. But agencies that never build the habit will eventually hit the one where a genuinely wrong approval — agent-sent, human-forwarded, whatever the source — triggers a real budget dispute, a scope fight, or a client asking pointedly who actually signed off on this.
The agencies that come out fine in that moment aren't the ones who never had an AI agent send them a confusing approval. They're the ones with a change log that shows, cleanly, that they asked the right question before spending the client's money.
Bottom line
Your clients are already routing approvals through their own AI agents, whether they've told you or not. The fix isn't suspicion — it's one small, consistent habit: confirm the human before you act on the money. Build that into the process now, before the first disputed approval forces you to build it under pressure.