Microsoft Copilot Studio approvals: what the human review actions do, and where they stop

Copilot Studio is Microsoft's tool for building agents on Microsoft 365 and the Power Platform. Its human review lives in agent flows, the fixed workflows that run beside or inside an agent. Two actions matter. Request for information pauses a flow and asks named people for input. Multistage approvals chain human and AI decisions. This page reads both from Microsoft's docs and marks where you should look closely before trusting them with money.
In one sentence: Copilot Studio can pause a flow and ask a person, and does it well, but it does not stand between the agent and your systems on every path.
Where it comes from
The approvals machinery predates agents. Power Automate's approvals connector offers types including "First to respond" and "Everyone must approve". With the second, "if any approver rejects, the approval request is considered rejected for all approvers"3. Copilot Studio's agent flows inherit that connector. They add a Request for information action under a Human review heading, and a multistage action that can include AI stages. Microsoft says multistage approvals "build upon standard approvals found in cloud flows"2.
What it does, per the docs
Request for information. The action lets a flow "pause execution" and "collect input from designated human reviewers before proceeding with subsequent steps"1. You set a title, a message and the reviewers' email addresses. Five input types are supported: text, yes/no, email, number and date1. The reviewer fills in the fields in Outlook and submits. The flow resumes with the values.
Three constraints are stated plainly, and each matters for a control:
- "The response from the first person to respond is used in the flow. Subsequent responses aren't processed."1
- "All requests are currently sent via Outlook only."1
- "Requests can't be sent to users outside of your tenant."1
Microsoft's examples fit back-office work. A claims flow asks field adjusters for repair estimates. A loan flow asks compliance officers for verification documents1.
Multistage approvals. One action, "Run a multistage approval". It "starts an approval, sends it to the required assignees, and waits for the approval requests to be completed before the rest of the flow continues"2. Inside it you build three kinds of stage:
- Manual stages, assigned to people, set to "First to respond" or "Everyone must approve"2.
- AI stages. You write instructions, attach documents, pick a model, and "the AI produces a clear Approve or Reject decision with clear rationale based on your instructions"2.
- Conditions between stages, which can "automatically approve, reject, route to another stage, or skip stages entirely"2.
The default routing is worth reading twice. If an AI stage approves, the approval moves on. If it rejects, "the approval ends as rejected". If it "fails to give an approve or reject decision, it continues to the next stage"2. Microsoft's worked example is expenses. Amounts under $5,000 approved by the AI stage "can bypass manager approval and automatically end as approved"2.
Copy three notes into your design review. AI stages need Copilot Credits: "If you don't have sufficient Copilot Credits, your approval stalls and doesn't proceed"2. On models: "Where possible, favor the more powerful models for approval decisions"2. And assigning the same approver to more than one stage "causes the flow to fail"2.
As of the 30 June 2026 update, multistage and AI approvals are marked preview. The docs say preview features "aren't meant for production use"2. Check the page before you build.
What it does well, and where it stops
Does well. If your approval already runs on Outlook and Teams, this is the shortest path to a person in front of an agent's action. Named assignees. Structured inputs. "Everyone must approve" for a two-signature step. Conditions that route by amount. That covers most of an approval policy table. The AI stage is an honest attempt at triage: let a model reject the obvious and pass the rest to a person, with its reasons.
Where it stops. Read the constraints as a control designer.
First response wins. Request for information to three people is a race, not a committee. Want two names? Use a multistage approval with "Everyone must approve", and put two different people in two stages.
Failure is permissive. An AI stage that rejects ends the approval. An AI stage that errors lets it continue. So a broken model gets more benefit of the doubt than a model that says no. For money, any failure to decide should hold. Conditions let you build that. The default does not.
Scope. These are steps inside one flow. Say your agent can reach the same connector through another topic or tool. An approval in a flow it did not take does not cover it. The approval controls its path. It does not control your system of record.
The record. Approval flows are saved in Dataverse. Responders need the Approvals User role "for their responses to be processed and persisted in their approvals history"4. Check what that history holds for one run. It will not, by itself, hold the version of the agent's instructions in force. Nor does it give an outsider a way to check nobody edited it.
Timeouts. Decide what the flow does when nobody answers. Make "nothing" an explicit choice.
What to check
- /01
Which path does your agent take to the system? Does every path pass through the approval?
- /02
For two signatures, are the stages assigned to two different people? Does the flow fail closed if one is missing?
- /03
What happens on AI-stage failure and on timeout? Read the routing you set, not the default.
- /04
Where is the approval history kept, and for how long? Can you export it with the run it belongs to?
- /05
Do reviewers see the agent's proposed action and evidence? Or a summary the flow author wrote?
- /06
Is the feature you rely on out of preview?
Where it is going
Microsoft is putting AI stages into the same approval fabric people use. Expect more channels than Outlook and more model choice. Our view: the gap to a control plane stays, by design. Copilot Studio governs what happens inside Copilot Studio. If your agents live entirely there, that may be enough. If they touch an ERP other tools also touch, the approval you want sits at the ERP's door, not inside one flow.
Gatehouse fit
Gatehouse sits at that door. Every action from any agent is checked against one set of signed rules before it runs. Held cases go to one named approver. A failure to decide holds rather than proceeds. The record is chained by SHA-256 and exported in open formats. If you are a Microsoft 365 shop with one approval to automate, Copilot Studio is cheaper and quicker, and Compare says so. If the agent commits money across systems, read the Gatehouse page.
At a glance
| Category | Vendors and tools |
|---|---|
| Product | Microsoft Copilot Studio, agent flows |
| Features covered | Request for information (human review). Multistage and AI approvals (preview as of June 2026) |
| Channels | Outlook for Request for information. Power Platform approvals for multistage |
| Approval types | First to respond. Everyone must approve |
| Docs dates | Request for information page 18 June 2026. Multistage page updated 30 June 2026 |
| Typical owner | A Power Platform admin builds it. The process owner is the assignee |
| The one test | Does every path from the agent to the system pass through the approval? |
Sources
- [1]Request information from human review in agent flows, Microsoft Copilot Studio docs, 18 June 2026learn.microsoft.com In text
- [2]Multistage and AI approvals in agent flows (preview), Microsoft Copilot Studio docs, updated 30 June 2026learn.microsoft.com In text
- [3]Create an approval flow that requires everyone to approve, Power Automate docslearn.microsoft.com In text
- [4]Get started with approvals, Power Automate docs, April 2026learn.microsoft.com In text
Read next

n8n human in the loop: Wait nodes, tool approval, and the who-clicked problem
n8n's three ways to put a person in front of an agent's action, read from its docs, and the difference between a link anyone can click and a verified approver.

What is an agent approval policy?
An approval policy decides which agent actions go ahead, which wait for a person, and which never happen. Most teams have a paragraph. You need a table.

The two-person rule for AI agents: overrides, dual authorisation, and Meta's Rule of Two
Two people to override a block. Where the rule comes from, what it should cover for an agent, and why Meta's 'Agents Rule of Two' is a different rule with a confusing name.