
Workflow Design
Human approvals in technical workflows
Design an approval gate around a defined decision, authorised responder, reviewed terms, deadline and separately confirmed action.
A human approval should authorise a defined action on the terms a person actually reviewed. The workflow must identify who may decide, present those terms, accept one valid decision, and check that the decision still applies before acting. Approval and completion of the later action are separate outcomes.
Take an equipment purchase. A manager reviews the proposed supplier and amount before an order is submitted. The purchasing system owns the current request details, the approval record identifies the terms reviewed, and the purchasing destination confirms whether an order was created.
Define the decision
Put the approval before the sensitive action. State the question plainly: “May this request, with this supplier and amount, be submitted?” Define who is eligible to answer and whether the rule requires one response, every assigned response or an ordered sequence. A group notification does not establish which rule applies.
Show the approver the business reference, proposed action, material terms and deadline, with a route to the authoritative record. Keep unnecessary personal or confidential details out of notifications.
| Approval state | Meaning | Permitted next step |
|---|---|---|
| Awaiting decision | A defined request is open | Hold the sensitive action |
| Approved | An authorised decision was accepted | Check that the reviewed terms still apply |
| Rejected | The action was declined | Follow the agreed rejection route |
| Expired | The deadline passed without a valid decision | Close the wait and assign unanswered work |
These are approval states. Approved does not mean that the purchase order exists.
Approval State Definitions and Next Steps
- Awaiting decision
- Request is open; hold the sensitive action until resolved.
- Approved
- Authorised decision received; verify reviewed terms still apply before acting.
- Rejected
- Action declined; follow the agreed rejection route.
- Expired
- Deadline passed without response; close request and reassign unmet work.
Choose a suitable wait
The Standard approvals connector includes a Create an approval action. It starts an automated approval but does not wait for it to complete. Microsoft documents that an approval flow can wait for 28 days; if the wait time exceeds 28 days, the flow fails while the request remains in the action centre. Check the chosen action and wait duration against the business deadline.
AWS Step Functions supports a task-token callback in supported Standard Workflow integrations; its integration table does not list that pattern for Express Workflows. A returned token resumes a task. The application that collects a human response still has to establish the person’s identity and authority.
For a decision that may outlive one execution, retain an approval record and define how a later valid response reaches a continuation path.
Using Microsoft Power Automate vs AWS Step Functions for Approvals
- Microsoft Power AutomatePros: Simple integration, built-in approval connector, clear state tracking. Cons: Max 28-day wait, limited Express Workflow support.
- AWS Step FunctionsPros: Supports long-running tasks via task-token callback, scalable for complex workflows. Cons: No Express Workflow support for callbacks, requires custom implementation.
Check the response channel
Microsoft’s Standard approvals connector accepts “Approve” and “Reject” for Basic or Await all approval types; those values are case-sensitive. Custom responses with “Everyone must approve” can fail because of data-size limits in the results field. Check that the selected response type fits the decision rule.
Do not assume every notification is an action surface. Microsoft says approval emails are actionable only when sent from a standard email account; a user-created email with a link can direct someone to the approval but cannot approve or reject it from within that email. Make the available response route clear in the notification.
Guest eligibility can affect whether a decision can be made. Microsoft says a guest needs a valid Power Automate licence to view or respond, and guests with pending tenant invitations are removed from the assignee list. If all assigned approvers have pending invitations, approval creation fails.
Microsoft documents that a Teams adaptive card does not automatically update if the approver responds through email or the approval action centre. A person may see a card whose status no longer matches the flow, so make the authoritative status clear.
Microsoft’s connector displays approval timestamps in UTC and shows the flow creator in approval details to prevent spoofing of approval sender identities. Explain the timestamp basis in the interface if users might otherwise mistake it for local time.
Key Compliance and Operational Metrics
- Maximum wait time (Power Automate)
- 28 days
- Guest access requirement
- Valid Power Automate licence needed to respond
- Timestamp format
- UTC (not local time)
- Email actionability
- Only standard email accounts support direct approval/rejection
Accept the decision and confirm the effect
When a response arrives, check the request ID, authenticated responder, authority, allowed outcome, current state and deadline. Accept it only under the defined decision rule. Keep repeated or late responses in the history without letting them release the action again.
Before acting, confirm that the current business record still matches the terms reviewed. For handling changes while approval is pending, see the supporting article.
After approval, retain the attempted downstream action and its confirmed result. A timeout after submission leaves the order outcome unknown until the purchasing destination can establish what happened.
In this guide
- Pausing a workflow until a named person approvesAssign an approval to an identified account, bind the decision to one waiting request and handle reassignment and repeat replies.
- Expiring an approval request that receives no responseSet a business deadline, close an unanswered approval through a controlled transition and prevent late responses from authorising an action.
- Recording who approved a sensitive actionRecord the actual approval responder, the terms reviewed and the separately confirmed result of the sensitive action.
- Handling changes to a record while approval is pendingClassify edits to a record under review, preserve the terms shown and prevent stale approval from authorising changed terms.



