Control & trust

Which AI agent platforms require human approval before an agent acts?

Of 984 vendors, 476 document full human oversight: approval steps, consent checkpoints, escalation rules, policy constraints and pause or resume control over a running agent. A near equal 437 document partial coverage, and only 71 document none.

Every vendor in the index is assessed against the same 14 point taxonomy from public documentation, and no vendor pays for placement. Counts on this page were measured across all 984 public vendors on August 10, 2026.

How the 984 vendors split

Full coverage476 vendors, 48.4%
Partial coverage437 vendors, 44.4%
No public evidence71 vendors, 7.2%

No public evidence means the reviewed sources did not document the capability. On this index that is a statement about the evidence, not proof that the capability is absent. See methodology.

What counts as full coverage

Full coverage means oversight is a configurable control rather than a property of one workflow: the buyer can decide which actions need sign off, who signs off, and what happens when nobody does. Partial commonly means a human handoff exists in one place, usually escalation to a live agent, without any general approval mechanism.

How to read these numbers

This is the most evenly split axis in the taxonomy, and the split itself is the finding. Almost every vendor documents something and fewer than half document a control. That is what an immature governance market looks like: escalation is built because customers complain, while approval policy is built because a security review demands it, and only the second survives an audit. Agent infrastructure and the browser lane sit lowest at 35 percent, which is exactly where autonomous action is least supervised, so if you are deploying agents with real write access, read this axis before the capability axes.

Leading platform for human oversight & guardrails in each use case

Picked mechanically: the highest total coverage vendor in each lane that documents full evidence on this axis, one vendor per row. Scores are out of 14.

  1. 1. UiPath, for enterprise operations agents

    13.5 / 14

    Full enterprise operations agents ranking · Compare the whole lane on all 14 axes

  2. 2. Automation Anywhere, for multi-agent platforms

    13 / 14

    Full multi-agent platforms ranking · Compare the whole lane on all 14 axes

  3. 3. NICE CXone, for customer support agents

    13 / 14

    Full customer support agents ranking · Compare the whole lane on all 14 axes

  4. 4. Salesforce, for GTM and revenue agents

    13 / 14

    Full GTM and revenue agents ranking · Compare the whole lane on all 14 axes

  5. 5. Agno, for agent infrastructure platforms

    12.5 / 14

    Full agent infrastructure platforms ranking · Compare the whole lane on all 14 axes

  6. 6. Appian, for agent builders

    12.5 / 14

    Full agent builders ranking · Compare the whole lane on all 14 axes

  7. 7. CrowdStrike, for security and SOC agents

    12.5 / 14

    Full security and SOC agents ranking · Compare the whole lane on all 14 axes

  8. 8. Emergence AI, for browser and computer-use agents

    12.5 / 14

    Full browser and computer-use agents ranking · Compare the whole lane on all 14 axes

  9. 9. Factory, for coding agents

    12.5 / 14

    Full coding agents ranking · Compare the whole lane on all 14 axes

  10. 10. Dataiku, for data analyst agents

    12 / 14

    Full data analyst agents ranking · Compare the whole lane on all 14 axes

  11. 11. Kubiya, for SRE and DevOps agents

    12 / 14

    Full SRE and DevOps agents ranking · Compare the whole lane on all 14 axes

  12. 12. Quiq, for voice agents

    12 / 14

    Full voice agents ranking · Compare the whole lane on all 14 axes

  13. 13. Innovaccer, for healthcare agents

    11.5 / 14

    Full healthcare agents ranking · Compare the whole lane on all 14 axes

Documented coverage by use case

Share of each lane documenting full coverage on this axis. Vendors that sit in two lanes count in both, the same rule the rankings and matrices use.

Use case Full coverage Share
multi-agent platforms 41 of 57 72%
SRE and DevOps agents 25 of 36 69%
customer support agents 77 of 115 67%
enterprise operations agents 191 of 319 60%
agent builders 66 of 114 58%
healthcare agents 44 of 77 57%
security and SOC agents 46 of 92 50%
coding agents 32 of 68 47%
voice agents 41 of 88 47%
GTM and revenue agents 60 of 144 42%
data analyst agents 25 of 67 37%
browser and computer-use agents 17 of 49 35%
agent infrastructure platforms 63 of 179 35%

Questions buyers ask

Is escalation to a human the same as an approval step?

No, and the difference matters. Escalation hands a conversation over after the fact. An approval step blocks an action until a person authorizes it. Many partial scores on this axis document the first and not the second.

Which lanes have the strongest oversight coverage?

Multi agent platforms at 72 percent and SRE and DevOps at 69 percent, followed by customer support at 67 percent. All three are places where an unsupervised agent can do visible damage quickly.

Does a low score mean the platform is unsafe?

It means the public evidence is thin. Unknown on this index means insufficient documentation, not proven absence, and it is a reasonable thing to put directly to the vendor in a security review.

The other 13 axes

No single axis decides a shortlist. Buyers who care about this one usually check knowledge grounding & rag and security, identity & governance next, or open the full taxonomy to see how the 14 axes fit together.

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.