Продолжая обсуждение из темы How do you limit what an AI Agent can do?:
Hi Luca,
Saw your comment about deterministic checks taking longer to develop — that’s exactly why we use the Human-in-the-Loop Gateway pattern via Telegram/Slack:
Instead of spending weeks coding rigid rule engines or relying on a secondary LLM (which is still probabilistic and can be tricked), you decouple the money execution entirely:
- No Direct Execution: The AI agent never has access to the actual
Stripe_Refundtool. It only triggers aRequest_Refund_Draftwebhook. - Instant Interactive Card: n8n sends an interactive card directly to the manager’s Telegram with inline buttons:
[ ✅ Approve $120 ]and[ ❌ Reject ], along with the customer’s summary. - Signed Webhook Execution: Only when a human physically taps
Approveon their phone, n8n calls the Stripe API to release the funds.
Zero prompt injection risk, zero code complexity, and it gives you 100% deterministic safety right now without spending weeks building custom backend checks.
I actually have an n8n workflow template built specifically for this Telegram refund gatekeeper. Happy to share the workflow JSON if you’d like to plug it in!