End User Confirmation and Choice for Agent Tool Execution #16654

Closed
opened 2026-02-21 19:27:04 -05:00 by yindo · 1 comment
Owner

Originally created by @icattlecoder on GitHub (Sep 2, 2025).

Self Checks

  • I have read the Contributing Guide and Language Policy.
  • I have searched for existing issues search for existing issues, including closed ones.
  • I confirm that I am using English to submit this report, otherwise it will be closed.
  • Please do not modify this template :) and fill in all the required fields.

1. Is this request related to a challenge you're experiencing? Tell me about your story.

Current Behavior

Currently, when an Agent in Dify determines that a Tool needs to be executed, it does so automatically without any user intervention. While this is efficient for many use cases, it can be problematic for tools that perform sensitive or irreversible actions, such as deleting or updating data.

Desired Behavior

I propose the introduction of a mechanism that allows for user confirmation before a Tool is executed. This would give the user the final say on whether to proceed with an action suggested by the Agent.
Ideally, this feature would be configurable and could offer different levels of control:

  • No confirmation (current behavior): For trusted, non-critical tools.
  • Confirmation for specific tools: Allow developers to flag certain tools (e.g., delete_record, update_database) as requiring user confirmation.
  • Confirmation for all tools: A global setting for agents where every tool execution must be approved by the user.

When a confirmation is required, the user interface could present the tool to be executed and its parameters, with options to "Approve" or "Deny" the execution.

2. Additional context or comments

No response

3. Can you help us with this feature?

  • I am interested in contributing to this feature.
Originally created by @icattlecoder on GitHub (Sep 2, 2025). ### Self Checks - [x] I have read the [Contributing Guide](https://github.com/langgenius/dify/blob/main/CONTRIBUTING.md) and [Language Policy](https://github.com/langgenius/dify/issues/1542). - [x] I have searched for existing issues [search for existing issues](https://github.com/langgenius/dify/issues), including closed ones. - [x] I confirm that I am using English to submit this report, otherwise it will be closed. - [x] Please do not modify this template :) and fill in all the required fields. ### 1. Is this request related to a challenge you're experiencing? Tell me about your story. ## Current Behavior Currently, when an Agent in Dify determines that a Tool needs to be executed, it does so automatically without any user intervention. While this is efficient for many use cases, it can be problematic for tools that perform sensitive or irreversible actions, such as deleting or updating data. ## Desired Behavior I propose the introduction of a mechanism that allows for user confirmation before a Tool is executed. This would give the user the final say on whether to proceed with an action suggested by the Agent. Ideally, this feature would be configurable and could offer different levels of control: - No confirmation (current behavior): For trusted, non-critical tools. - Confirmation for specific tools: Allow developers to flag certain tools (e.g., delete_record, update_database) as requiring user confirmation. - Confirmation for all tools: A global setting for agents where every tool execution must be approved by the user. When a confirmation is required, the user interface could present the tool to be executed and its parameters, with options to "Approve" or "Deny" the execution. ### 2. Additional context or comments _No response_ ### 3. Can you help us with this feature? - [ ] I am interested in contributing to this feature.
yindo added the 💪 enhancement🤖 feat:agent labels 2026-02-21 19:27:04 -05:00
yindo closed this issue 2026-02-21 19:27:04 -05:00
Author
Owner

@crazywoola commented on GitHub (Sep 2, 2025):

We are already working on this feature, and there are several issues related to this feature already.

@crazywoola commented on GitHub (Sep 2, 2025): We are already working on this feature, and there are several issues related to this feature already.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#16654