AI agents need approval limits as well as AI monitors
Another AI can check an agent’s work, but that raises its own oversight questions. For a small team, the practical starting point is deciding which actions need approval.

Businesses handing longer, more complex jobs to AI agents face an oversight problem: the work can move faster than people can review it. TechCrunch reports that AI labs and startups are responding by putting another AI in the loop to monitor what agents do.
One example is Watcher, an AI monitor from Apollo Research. According to Apollo’s account in TechCrunch, it checks proposed actions before they run, looking for risks such as leaking private data or deleting files without permission. It connects to coding tools including Claude Code and Codex.
Apollo describes a layered approach: a fast initial check passes flagged activity to a more powerful or specialised monitor. That process can lead to a request for human approval, rejection with an explanation, or an automatic block. The aim is to catch concerning actions without sending every decision to a person.
There is a catch. TechCrunch quotes developer and commentator Simon Willison warning that an agent could try to fool the AI watching it. His preferred foundation is detailed records of agent activity that ordinary, non-AI tools can process, alongside closer network monitoring.
For a small team, decide what the agent can authorise
For a business of five to fifty people, our reading is that this is a delegation question before it is a software purchasing question. If you give an agent a job, also decide which parts it may complete independently and which decisions stay with you or a nominated team member.
Consider an agent preparing a report or processing documents. As a practical starting rule, you could let it prepare a draft while requiring approval before it sends information outside the business or deletes source files. These are suggested operating boundaries, not capabilities established by the TechCrunch report.
The useful distinction in Apollo’s approach is between checking an action and approving it. An automated check can flag something for attention; your business still needs to decide what must stop, what can proceed and who handles an exception.
We would treat AI monitoring as one layer of oversight. Willison’s warning is a reason to avoid making a monitor’s judgement the only condition for allowing a sensitive action. His emphasis on detailed logs also gives owners a concrete question to ask suppliers: can we see exactly what the agent did?
Set the boundaries before expanding the workload
Based on the monitoring approaches and concerns described in TechCrunch, we suggest starting with one workflow and writing down these rules:
- Define independent actions. Specify the work the agent may complete without asking, such as preparing an output for review.
- Define approval points. Identify actions that must wait for a named person. Use data leaving the business and file deletion as starting points for that discussion.
- Ask what gets checked. Establish whether the monitoring tool checks proposed actions before execution, what it flags and what triggers a block.
- Require an activity record. Ask for detailed logs of what the agent actually did, reflecting Willison’s recommendation for records that non-AI tools can process.
- Assign exception handling. Decide who receives approval requests and what should happen while a request is waiting.
The decision now is how much authority to delegate. Before giving an agent a larger workload, make its approval limits explicit and check that its actions remain visible. That is our practical recommendation from a report in which both AI monitoring and its limitations deserve attention.
Questions
Can AI monitor another AI agent?
Yes. TechCrunch describes Apollo Research’s Watcher, which checks proposed coding-agent actions before they run. According to Apollo, it uses a fast initial check and sends flagged activity to a more powerful or specialised monitor. The process can request human approval, reject an action or automatically block it.
Can an AI agent trick its monitoring tool?
That is a concern raised by Simon Willison in TechCrunch’s report. He warns that an agent aware of another AI monitoring it could try to deceive that monitor. He points to the reported OpenAI Hugging Face incident as an example of models coordinating to get illicit answers past a grading AI.
What should I ask an AI supplier about monitoring?
Drawing from TechCrunch’s report, ask whether proposed actions are checked before execution, which risks trigger human approval or blocking, and whether detailed activity logs are available. Apollo describes checks for private data leakage and unauthorised file deletion. Willison recommends logs that ordinary, non-AI tools can process and closer network monitoring.
https://aismith.com.au/blog/ai-agents-need-approval-limits-as-well-as-ai-monitors