surehand
All articlesVendors

n8n human in the loop: Wait nodes, tool approval, and the who-clicked problem

Reference6 min readSurehand

n8n is a workflow automation tool with an AI Agent node. Teams pick it to build agents themselves. It gives you three ways to put a person in the path. A Wait node pauses a workflow. A Human review step gates individual tools the agent may call. Send and Wait for Response asks in Slack, Teams, Gmail and more. This page reads all three from n8n's docs. Then it asks what each proves about who approved what.

In one sentence: n8n can pause and ask a person before a tool runs, and whether you know who answered depends on the node you used.

Where it comes from

n8n's founder states the design stance on the company blog. "Trustworthy AI systems combine deterministic workflows, probabilistic models, & human oversight. Automation ensures control, AI handles complexity, & humans own risk, edge cases, and final responsibility"5. The Wait node is the general pause-and-resume building block. Human review for tools and Slack approvals arrived as the AI Agent node learned to call tools that change things.

The licence matters to you as a buyer. n8n uses its own Sustainable Use License, "a fair-code software license created by n8n in 2022"4. You may use or modify it "only for your own internal business purposes or for non-commercial or personal use"4. Enterprise features sit under a separate licence4. Running it inside your company is fine. Embedding it in something you sell needs a commercial agreement.

What it does, per the docs

The Wait node. It pauses and "offloads the execution data to the database"2. When the resume condition is met, "the workflow reloads the data and the execution continues"2. It resumes after an interval, at a set time, on a webhook call, or on a form submission2. The webhook option makes a URL unique to the run. It supports authentication and a "Limit Wait Time" deadline2. This is a building block. It knows nothing about approvals until you build one around it.

Human review for tools. The one built for agents. You can "require human approval before an AI Agent executes a specific tool"1. The workflow pauses. A person sees "which tool the AI wants to use and with what parameters"1. On approve, "the tool executes with the input specified by the AI"1. On deny, "the action is canceled and the AI is informed of the rejection"1.

You can gate all tools or selected ones. The docs call that "more precise control than general output gating"1. Requests can go through n8n Chat, Slack, Discord, Telegram, Teams, Gmail, WhatsApp, Google Chat or Outlook1. A $tool variable lets the reviewer's message show the tool name and parameters1. The docs also say to describe the review setup in the system prompt, so the agent handles a denial well1.

Slack approvals. The Slack node's Send and Wait for Response, set to approval, lets approvers "approve or decline directly inside Slack", and "the output records who responded"3. n8n's own comparison of the two modes is the most important table in these docs.

With the default link buttons, "anyone who can click the link" can respond3. The docs' verdict on them: "Signed links: no one can tamper with the URL or its action, but anyone who has the link can respond, and n8n can't tell who clicked"3.

With Slack interactive approvals, "n8n verifies every callback came from Slack (using Slack's request signing) and checks the responder against your approver list"3. The output adds the responder's ID, name, username and email3. Anyone not on the list gets a private notice, "and the workflow keeps waiting"3.

What it does well, and where it stops

Does well. Tool-level review is the right granularity. Gate sending email and updating records. Let order lookups run freely. That is what an approval policy table asks for, and n8n draws the line per tool. The reviewer sees the actual parameters, not a summary. Slack mode, set up properly, gives you a named responder verified by Slack's signature. And it can all run on your own server.

Where it stops. Four things, all visible in the docs.

Who clicked. The default approval is a signed link with no identity. For anything that moves money, that is a button, not an approval. Use Slack interactive mode with Restrict Who Can Approve. Test that an unlisted user leaves the workflow waiting3.

Per path, not per system. A Human review step protects the tools attached to it. A second workflow, another agent, or a raw HTTP Request node hitting the same API is not covered. The control lives in the workflow. So every workflow that can write must carry it.

The record. You get n8n's execution data: tool, parameters, approval output, timestamp, and in Slack mode the responder. You decide where that is kept and for how long. You also need a way to show an outsider nobody altered it. n8n does not chain or seal executions.

Deny is not refuse. A denied call tells the agent no. The agent may try another route. The docs say to write the system prompt so it handles denial1. That is a request to the model. The only hard refusal is not connecting the tool at all. That is a good control, and one you have to remember.

What to check

  1. /01

    Which approval mode are you using? Does the output name a verified responder?

  2. /02

    Does every workflow that can write carry a Human review step? Or only the one you built first?

  3. /03

    What happens when Limit Wait Time runs out? Does the action proceed, or does the run end and record a timeout?

  4. /04

    Where do executions go, and for how long? Can you export the approval with the run?

  5. /05

    Are you inside the Sustainable Use License? Or does your use need an enterprise agreement?

  6. /06

    Who else can reach the instance?

Where it is going

n8n is adding channels and identity to its approvals rather than building a policy layer. The Slack approvals docs read like the first of a series. Our view: it stays a workflow tool with good human-in-the-loop parts, and that is the right thing for it to be. Teams outgrow it when several agents hit one ERP and need one set of rules and one record across them.

Gatehouse fit

Gatehouse is that one set of rules and one record. Signed rules are checked before every action from any workflow or agent. Holds go to one named approver. A refusal is one the agent cannot route around. The record is chained by SHA-256 in open formats. For one internal workflow with one approval, n8n's Human review for tools is a good and cheaper answer. Compare says when to pick it. For agents that commit money across systems, see the Gatehouse page.

At a glance

CategoryVendors and tools
Productn8n (self-hosted or n8n Cloud)
MechanismsWait node. Human review for AI Agent tools. Send and Wait for Response in channel nodes
Approver identityAnonymous with default link buttons. Verified with Slack interactive approvals and an approver list
LicenceSustainable Use License (fair-code). Enterprise features under a separate licence
Typical ownerThe workflow builder. The reviewer named in the channel
The one testDoes the approval output name a verified person?

Sources

  1. [1]Human-in-the-loop for tools, n8n docsdocs.n8n.io In text
  2. [2]Wait node, n8n docsdocs.n8n.io In text
  3. [3]Approvals (Slack node, Send and Wait for Response), n8n docsdocs.n8n.io In text
  4. [4]Sustainable Use License, n8n docsdocs.n8n.io In text
  5. [5]Human in the loop automation, n8n blogblog.n8n.io In text

Read next

[ your next step ]

Bring us the queue nobody wants.

One process, studied in writing. You keep the document, whatever it says.

support@surehand.io