Where you approve
On the review screen: the original messages, what each check found and where the facts came from, the draft, and the rule that produced it. You have three verdicts.
Approve. It sends and writes the record.
Edit, then approve. Your version sends, and the difference between what was drafted and what you sent gets recorded.
Kill. It stops, and it asks you why in one line, so the answer can turn into a rule later.
The gate has no side door. If there's any path where the system sends without you, you don't have an approval gate.
Time the review. If it takes longer than writing the reply, inspect the evidence, draft quality, and review process before expanding the workflow.
When it can't tell
Define what happens when the request, the rules, or a source cannot be trusted.
- The form and the email disagree about what they want.
- A near-duplicate that isn't clearly the same request.
- Two routing rules match the same request.
- The request mentions something sensitive: a dispute, a deadline already passed, a regulated category.
- The extraction confidence sits under whatever line you set.
- A system the workflow needs is down or slow.
On any of those it stops, writes down what it knows and what it couldn't resolve, and puts it in front of a person with the original message attached. It doesn't send a vague reply to cover the gap. A hedged reply to a customer is worse than a slow one.
Count exceptions and read them weekly. Review the repeated reasons, and check whether rule changes reduce those cases without hiding failures.