Control & trust
Which AI agent platforms require human approval before an agent acts?
Of 946 vendors, 476 document full human oversight: approval steps, consent checkpoints, escalation rules, policy constraints and pause or resume control over a running agent. Another 401 document partial coverage, and only 69 document none.
Every vendor in the index is assessed against the same 14 point taxonomy from public documentation, and no vendor pays for placement. Counts on this page were measured across all 946 public vendors on September 30, 2026.
How the 946 vendors split
No public evidence means the reviewed sources did not document the capability. On this index that is a statement about the evidence, not proof that the capability is absent. See methodology.
What counts as full coverage
Full coverage means oversight is a configurable control the vendor ships rather than a property of one workflow: the buyer can decide which actions need sign off, who signs off, and what happens when nobody does. Partial commonly means a human handoff exists in one place, usually escalation to a live agent, or a boundary that is stated rather than enforced. A gate the buyer already owns, such as a draft pull request awaiting review in their own repository, is a delivery convention and not the vendor's mechanism.
How to read these numbers
This is one of the most evenly split axes in the taxonomy, and the split itself is the finding. Almost every vendor documents something, and only about half document a control. That is what an immature governance market looks like: escalation is built because customers complain, while approval policy is built because a security review demands it, and only the second survives an audit. Data analyst agents at 36 percent and the browser lane at 39 percent sit lowest, with agent infrastructure close behind at 43, which is exactly where autonomous action is least supervised, so if you are deploying agents with real write access, read this axis before the capability axes.
Leading platform for human oversight & guardrails in each use case
Picked mechanically: the highest total coverage vendor in each lane that documents full evidence on this axis, one vendor per row. Scores are out of 14.
-
1. Appian, for enterprise operations agents
14 / 14Full enterprise operations agents ranking · Compare the whole lane on all 14 axes
-
2. FLOWX.AI, for multi-agent platforms
14 / 14Full multi-agent platforms ranking · Compare the whole lane on all 14 axes
-
3. Gumloop, for GTM and revenue agents
14 / 14Full GTM and revenue agents ranking · Compare the whole lane on all 14 axes
-
4. Mastra, for agent infrastructure platforms
14 / 14Full agent infrastructure platforms ranking · Compare the whole lane on all 14 axes
-
5. ServiceNow, for customer support agents
14 / 14Full customer support agents ranking · Compare the whole lane on all 14 axes
-
6. UiPath, for agent builders
14 / 14Full agent builders ranking · Compare the whole lane on all 14 axes
-
7. GitHub Copilot, for coding agents
13.5 / 14Full coding agents ranking · Compare the whole lane on all 14 axes
-
8. Dataiku, for data analyst agents
13 / 14Full data analyst agents ranking · Compare the whole lane on all 14 axes
-
9. Adopt AI, for browser and computer-use agents
12.5 / 14Full browser and computer-use agents ranking · Compare the whole lane on all 14 axes
-
10. ElevenAgents, for voice agents
12.5 / 14Full voice agents ranking · Compare the whole lane on all 14 axes
-
11. Torq, for security and SOC agents
12.5 / 14Full security and SOC agents ranking · Compare the whole lane on all 14 axes
-
12. Edge Delta, for SRE and DevOps agents
12 / 14Full SRE and DevOps agents ranking · Compare the whole lane on all 14 axes
-
13. Cohere Health, for healthcare agents
10.5 / 14Full healthcare agents ranking · Compare the whole lane on all 14 axes
Documented coverage by use case
Share of each lane documenting full coverage on this axis. Vendors that sit in two lanes count in both, the same rule the rankings and matrices use.
| Use case | Full coverage | Share |
|---|---|---|
| multi-agent platforms | 34 of 52 | 65% |
| SRE and DevOps agents | 23 of 37 | 62% |
| enterprise operations agents | 179 of 297 | 60% |
| coding agents | 38 of 64 | 59% |
| agent builders | 67 of 115 | 58% |
| browser and computer-use agents | 24 of 42 | 57% |
| customer support agents | 61 of 113 | 54% |
| security and SOC agents | 40 of 85 | 47% |
| healthcare agents | 30 of 69 | 43% |
| data analyst agents | 25 of 59 | 42% |
| agent infrastructure platforms | 75 of 186 | 40% |
| GTM and revenue agents | 53 of 138 | 38% |
| voice agents | 21 of 83 | 25% |
Recent verified changes from the vendors named above
Capability coverage is not a static picture. These are the most recent sourced change log entries for the platforms listed above, newest first, one per vendor. Scores on this page update as entries like these are verified.
-
UiPath human approval / guardrails
High impactAdministrators can now bring their own safety vendor into UiPath's AI Trust Layer, in preview, so agent guardrails run under the customer's own vendor agreement and region. Azure AI Language, Azure Content Safety and Noma are supported, checks can be enforced across the organization, and each evaluation is recorded in the agent trace.
October 1, 2026 · Partially Verified · All UiPath changes
-
GitHub Copilot human approval / guardrails
High impactGitHub Copilot for JetBrains 1.18.0 introduced assisted approvals in public preview, automatically approving lower risk tool calls while requesting human decisions for higher risk actions. The release also added persistent controls for individual MCP tools, shared organization skills and instructions, and the ability to rewind a conversation and its file changes when editing an earlier request.
September 22, 2026 · Verified · All GitHub Copilot changes
-
ServiceNow human approval / guardrails
High impactServiceNow rebranded Now Assist for Creator to ServiceNow Otto for Creator and introduced several updates to its Build Agent. The release adds the ability to define custom skills and rules for the agent, allows developers to run and roll back scripts directly from the chat panel, and enables the agent to build within isolated Developer Sandboxes.
August 6, 2026 · Verified · All ServiceNow changes
-
Gumloop human approval / guardrails
High impactHuman-in-the-loop for agents lets agents pause mid-task to request approval before running a tool, or ask a question with options, then resume where they left off in agent chats and Slack.
June 16, 2026 · Verified · All Gumloop changes
-
Mastra deployment / data residency
Medium impactAny environment on Mastra's hosted platform can now get a Postgres database that accepts connections only from inside the same private network. It is created with one CLI command or at deploy time, placed in the environment's region and wired in automatically.
October 1, 2026 · Verified · All Mastra changes
Full change log · updated weekly across the whole index
Questions buyers ask
Is escalation to a human the same as an approval step?
No, and the difference matters. Escalation hands a conversation over after the fact. An approval step blocks an action until a person authorizes it. Many partial scores on this axis document the first and not the second.
Which lanes have the strongest oversight coverage?
SRE and DevOps at 72 percent, then multi agent platforms and customer support, both at 67 percent. All three are places where an unsupervised agent can do visible damage quickly.
Does a low score mean the platform is unsafe?
It means the public evidence is thin. Unknown on this index means insufficient documentation, not proven absence, and it is a reasonable thing to put directly to the vendor in a security review.
The other 13 axes
No single axis decides a shortlist. Buyers who care about this one usually check knowledge grounding & rag and security, identity & governance next, or open the full taxonomy to see how the 14 axes fit together.