1
Curious builder0 XP earned · 300 to level 2
0 daysFinish a lesson to begin
Badge collection0 of 6 unlocked
46 small wins to finish your pathNext lesson →
A morning at the desk
A morning at the desk is three messages from two customers: a policy question, a refund that goes through, and a refund the tool refuses.
Last updated: 27 Sep, 2026 · LangChain 1.4
The guards from lesson 34 are in place. Now watch the desk handle a real morning: two customers and three messages, including a refund that is approved and still refused.
A policy question first
Ravi asks a policy question first. It needs no order tool.
from chat import say
say("ravi", "How long does a refund take?", "ravi-1") # a policy questionRefunding his own order
Then he asks to refund his own order. The refund pauses for approval before it runs.
say("ravi", "Please refund A17", "ravi-1") # A17 is Ravi's orderRefunding an order that is not hers
Mei asks to refund the same order. Approval lets the call run, and the tool still refuses it, because A17 is not hers.
say("mei", "Please refund A17", "mei-1") # A17 is not Mei'sRunning the morning's three messages
The three messages in order, sent through say.
from chat import say
say("ravi", "How long does a refund take?", "ravi-1")
say("ravi", "Please refund A17", "ravi-1")
say("mei", "Please refund A17", "mei-1")What the morning showed
- The policy question was answered from the refunds document, not from anything the model knew.
- Ravi's refund paused, was approved, and ran: A17 is his.
- Mei's refund of A17 also paused and was also approved, and the tool still refused it. Approval says a call may run; the tool decides whether it should.
Approval vs the owner check
| Approval (human-in-the-loop) | The owner check (the tool) | |
|---|---|---|
| Question it answers | May this call run? | Should this call succeed? |
| Who decides | The person at the desk | refund_order, from the context |
| Mei's refund of A17 | Approved | Refused, not her order |
When an action needs approval
- Any action a human must approve before it runs.
- Guarding the same action twice: a person approves it, and the code still checks it is allowed.
Watch out. Approval is not authorization. Approve Mei's refund of Ravi's order and the tool still refuses it, because the owner check runs inside the tool. Drop that check and approval is the only thing between a customer and someone else's refund.
Related
- Previous: The desk's guardrails
- Next: The desk's saved threads
- Reference: Human-in-the-loop
Try it yourself
- Change
sayto reject refunds instead of approving them, and run the morning again. - Ask a question that needs no tool at all and follow it through the drawing.
- Give Mei an order of her own in
ORDERSand refund it.
This is what real progress feels like.