AI Automation, RAG & MCP
5 min read
By UnlockLive IT engineering team
Workflow diagram of an AI agent proposing an action, a person approving it in Slack or Telegram, and n8n executing and logging it

AI agents can now read a support ticket, check an order, decide a refund is due and draft the reply. The hard part is not the reasoning. It is trusting the agent to press the button. One wrong refund, one email to the wrong customer, or one overwritten record can undo the time the agent saved.

So many teams stop at drafts. A person still copies the draft, opens three systems and does the work by hand. The agent helps, but the slow, repetitive part remains. There is a middle path: let the agent prepare the action, and let a person approve it in one click.

What this does

MCP (Model Context Protocol) is an open standard introduced by Anthropic. It lets AI assistants such as Claude, and other clients that support it, connect to tools and data through small programs called MCP servers. Support varies by AI client, so check each client's current documentation before you plan a rollout.

In this pattern, MCP tools give the agent controlled access to your systems for reading context and proposing actions. n8n, a workflow automation platform, runs the process around it. When the agent proposes an action, n8n sends an approval request to Slack or Telegram. A named person approves or rejects. Only then does n8n execute the action and log the outcome.

Typical actions include:

  • Issuing a refund below a set amount after checking the order.
  • Sending a customer email the agent drafted.
  • Updating a CRM record or ticket status.
  • Creating a purchase request or a calendar booking.

A refund example

A customer emails to say an item arrived damaged. The workflow starts. The agent reads the email, looks up the order and checks the refund policy through read-only tools. It finds the order is recent, the amount is within the limit, and the customer has no history of disputes.

The agent proposes a refund for that item, with a two-line reason. n8n confirms the amount is under the limit. It then posts a message to the support channel in Slack. The message shows the customer, order, amount and reason, with approve and reject options. A team lead reads it, taps approve, and moves on.

n8n issues the refund through the payment platform's API, sends the customer a templated confirmation, and writes a log entry. If the lead had rejected it, the case would return to the queue for a person to handle. Either way, there is a clear record of what happened and who decided.

How it works, step by step

  1. Trigger. An event starts the workflow, such as a new ticket, an inbound email or a form submission.
  2. Gather context. The agent uses read-only MCP tools to look up the order, customer history and policy.
  3. Propose. The agent returns a structured proposal: the action, the inputs, and a short reason.
  4. Validate. n8n checks the proposal against hard rules, such as refund limits or allowed recipients. Anything outside the rules is rejected or escalated.
  5. Ask for approval. n8n posts a short preview to Slack or Telegram with approve and reject options, then waits.
  6. Execute. On approval, n8n runs the action through the system's API, using narrowly scoped credentials.
  7. Log. The workflow records the proposal, the approver, the time, the result and the previous values.
  8. Roll back if needed. For reversible actions, a documented rollback restores the previous state from the log.

Tools we use

  • n8n, often self-hosted, for workflows, approvals, retries and scheduling. Our comparison of self-hosted n8n vs Zapier vs Make explains why.
  • MCP SDKs in Python or TypeScript for the agent's tools.
  • Python with FastAPI for custom logic and integration layers.
  • Slack or Telegram for approvals, since that is where your team already works.
  • Your existing systems: help desk, CRM, payment platform or ERP.

Features in n8n, chat platforms and AI clients change. Check each vendor's current documentation before you design approval steps.

What you need to get started

  • One process with a clear, repeated action, such as small refunds or ticket updates.
  • Written rules for that action: limits, exceptions and who may approve.
  • API access to the systems involved, with a test environment.
  • A Slack workspace or Telegram group for approvals.
  • A named owner who reviews the logs in the first weeks.

Typical scope and timeline

As an estimate, a first workflow with read-only context and one approved, low-risk action typically takes one to three weeks. The range depends on how many systems are involved and how clear the business rules are. Each further action is usually faster, because the approval and logging pattern is reused.

Risks and how we handle them

Wrong proposals

The agent can misjudge a case. Hard rules in n8n catch anything outside limits, and the human approver catches the rest.

Approval fatigue

If every message needs approval, people start clicking without reading. Keep previews short, show only what matters, and remove approval only for actions that have proven safe and reversible.

Prompt injection

A customer email can contain instructions aimed at the agent. Because nothing runs without validation and approval, injected text cannot act on its own. Our MCP server security checklist lists the other controls.

Irreversible actions

Some actions cannot be undone, such as a sent email. These get stricter rules, and sometimes a second approver.

Start with low-risk actions

Order your rollout by risk. Begin with internal, reversible actions such as tagging tickets or updating a status. Then move to customer-facing drafts that a person sends. Only then automate refunds, outbound emails and record changes with approval. Our guides to AI support ticket triage and AI email inbox triage are good first steps.

Done well, this can carry a large share of routine work. In our Branify AI customer service project, 70% of tickets were resolved without a human.

When not to build this

If a rule-based automation can do the job with no judgement involved, skip the agent. It will be cheaper and more predictable. If the action is rare, a person doing it by hand is fine. And if your help desk or CRM already offers a built-in AI feature with approvals that fits, try that first.

How UnlockLive can help

UnlockLive IT is a Toronto-headquartered software agency with its own engineering team. We build these integrations for companies in the US, Canada, the UK and Australia. Our MCP server development service covers scoping, the threat model, the build, deployment and ongoing maintenance. Our AI Workflow Automation service designs the n8n workflows, approval steps, logging and rollback around them.

If you want a second opinion on scope or risk, book a free 30-minute call. Bring one or two questions your team asks every week, and we will tell you honestly whether an MCP server is the right tool.

Frequently asked questions

What is human-in-the-loop for AI agents?

It means a person reviews and approves an AI agent's proposed action before it runs. The agent does the preparation, such as reading the case and drafting a refund or email, and a human makes the final decision.

Can n8n send approval requests to Slack or Telegram?

Yes. n8n can post a message with approve and reject options to Slack or Telegram and wait for the response before continuing. Check n8n's current documentation for the exact nodes and options available in your version.

How is MCP different from n8n?

MCP is a standard way for AI assistants to call tools and read data. n8n is a workflow automation platform that runs multi-step processes, including waiting for approvals. They work well together: the AI uses MCP tools to gather context and propose actions, and n8n runs the approved process.

Which actions should we automate first?

Start with low-risk, reversible actions where mistakes are easy to spot and fix, such as drafting replies, tagging tickets or updating an internal status. Move to refunds, customer emails and record changes once approval and logging have proven reliable.

What happens if an approved action was wrong?

Plan for that before launch. Each action type should have a documented rollback, such as reversing a record change from the logged previous value. Some actions, like a sent email, cannot be undone, which is why they need stricter approval.

How do you build an n8n AI agent that waits for approval?

Let the agent prepare the action, such as a drafted refund or email, but not execute it. The workflow posts the proposal with approve and reject options to Slack or Telegram and waits for the reply. Only an approval triggers the real step, which is logged with who approved it. Start with low-risk, reversible actions before moving to bigger ones.

How we can help

  • AI Workflow AutomationAI automations on self-hosted n8n for lead follow-up, invoices, support triage, reports and documents, with Telegram, WhatsApp or Slack alerts and approvals.
  • MCP Server Development ServicesCustom Model Context Protocol (MCP) servers that expose your APIs, databases, and internal tools to Claude, Cursor, ChatGPT, and any MCP-compatible AI.
  • AI Agent DevelopmentProduction AI agents with LangChain, OpenAI Agents SDK, and Claude. RAG, tool use, multi-agent orchestration, voice, and browser-using agents.

Talk to an engineer about your project

Tell us what you are building. We reply within one business day with a candid view on scope, approach and effort.

Book a free strategy call

Written by the UnlockLive IT engineering team. UnlockLive IT Limited works with clients through its Toronto headquarters and delivers engineering from its Dhaka delivery centre. About us

Related articles

AI Automation, RAG & MCPAI Build vs Buy: An Honest Framework for Choosing Off-the-Shelf or CustomAI Automation, RAG & MCPStop Retyping Forms and PDFs: AI Document Extraction into Your ERP or CRMAI Automation, RAG & MCPShared Inbox Overload? AI Email Triage Sorts and Routes info@ and sales@

Contact Us

Fill out the form below and our team will get back to you shortly to assist with your inquiry.