All insights
How it works

Should an ATS assistant act without your approval?

Mostly no. Routine internal work can run alone, but anything a candidate sees needs one-click approval. Why propose-and-confirm beats full autonomy.

RE
Recruitifly Editorial
Editorial
2026-06-12·6 min read
On this page

For most actions, no. An assistant that prepares work is a time saver; an assistant that sends, rejects and makes offers without a human looking first is a liability waiting for a busy Tuesday. The control model that holds up in practice is propose-and-confirm: the assistant does the preparation completely, and a recruiter approves the result with one click. Internal bookkeeping can run on its own; anything a candidate sees, or anything that changes a candidate’s outcome, should not.

How does propose-and-confirm work?

The assistant does everything except the final decision. Ask it to turn down a candidate gracefully and it reads the job, the notes and the conversation history, writes a personal rejection in your tone, and presents the whole thing as a pending action: the message, the recipient, the stage change it implies. You read it, edit it if you want, and confirm. Only then does anything leave the building.

The point is the division of labour. Software is excellent at gathering context and producing a strong first version. It is not accountable, and cannot be, for the judgment call. Recruitifly’s assistant Fly is built this way on every screen: it can draft the outreach, prepare the stage move or assemble a shortlist, but each change lands as a proposal you confirm or cancel. Most serious tools have some version of this; what differs is the default setting, and defaults are what fire at five on a Friday.

What goes wrong when an assistant acts alone?

Three failure modes show up over and over.

Wrong-candidate messages. Automation operates on records, and records contain duplicates, merge errors and two people named Mark. A human glancing at a draft catches the wrong Mark instantly; an autonomous send turns a small data problem into a rejection email to your best finalist. That kind of trust does not come back with an apology.

Premature rejections. Screening models misread career breaks, non-linear CVs and job titles that do not match a tidy taxonomy. With auto-rejection switched on, those candidates vanish silently, nobody learns what was lost, and if the misreads correlate with a protected characteristic you have built a discrimination claim with a timestamp.

Compliance exposure. Under GDPR, candidates have protections against decisions with significant effects made solely by automated means, and a rejection nobody reviewed is exactly that. When a candidate asks why they were turned down, “the system decided” satisfies neither a regulator nor a court. Data handling in hiring is a topic of its own; our guide to a GDPR-compliant ATS covers it in depth.

Where should the approval line sit?

One rule covers most cases: internal and reversible can run automatically; external or outcome-changing needs a person.

Action Auto-approve? Why
Logging calls, notes and activity Yes Internal and editable
Reminders and nudges to your own team Yes Nobody outside sees them
Parsing CVs into profiles Yes Reversible, no outbound effect
Drafting messages of any kind Yes, as drafts Writing is not sending
Sending outreach or interview invitations No, approve first Candidate-facing and reputational
Stage moves that trigger candidate emails No, approve first A click becomes a communication
Rejecting a candidate Never automatic Outcome-changing, legally sensitive
Extending or adjusting an offer Never automatic Contractual consequences

If a task sits in the top half of that table, automate it without guilt. The broader question of which recruiting work is worth automating at all gets its own treatment in what can actually be automated in recruitment.

Does approval-first cancel the time savings?

No, because the costs are asymmetric. Drafting a thoughtful rejection means rereading notes, finding the right tone and writing: ten to twenty minutes. Reviewing a well-prepared draft of that same message: seconds. The approval step keeps a sliver of the work and all of the control, and it doubles as your error filter. The first wrong-name email you catch in review pays for every approval click you will ever make.

It scales, too. Approving twelve prepared follow-ups takes a couple of minutes; writing twelve takes an afternoon. The preparation, not the decision, was always the expensive part, which is why approval-first assistants still change the economics of a desk without changing who is responsible for it.

What does the EU AI Act expect from hiring tools?

Recruitment is named explicitly in the Act. Systems used to recruit or select candidates, to filter applications or to evaluate applicants are classified as high-risk, with the obligations for those systems applying from 2 August 2026. Two of them matter day to day.

First, human oversight by design. High-risk systems must be built so the people using them can understand what the system did, decline its output, and intervene or stop it. The Act even names automation bias: oversight has to guard against the human tendency to wave through whatever the machine suggests. An interface that shows each proposed action before it executes is this requirement made concrete.

Second, oversight by competent people. Deployers, meaning the employer or agency using the tool, must assign oversight to someone with the training and authority to act on it. In practice: approvals should be done by people who actually read them, “approve all” should make you nervous at scale, and you should be able to show afterwards who approved what and when. Tooling is starting to support that paper trail directly; Recruitifly’s Compliance Engine add-on, for instance, includes EU AI Act impact records in its regional bundle.

None of this prohibits assistants in hiring. It prohibits unsupervised ones.

What should you ask a vendor about autonomy?

Whether you are evaluating Recruitifly, Workable, Greenhouse or Teamtailor, the questions are the same five:

  1. What exactly can the assistant do without my confirmation? Ask for the list.
  2. Can I see every pending and executed action in one place?
  3. Is there a per-action record of who approved what, and when?
  4. Which actions can be undone, and which are irreversible?
  5. Can autonomy be widened gradually as trust builds, rather than all at once?

A vendor with good answers will be glad you asked. A vendor selling fully autonomous hiring is selling you the liability along with the licence.

Recruitifly is in private beta at the moment. If you want to see propose-and-confirm on a live role, talk to us and bring a real vacancy. Watching the assistant prepare the work while you keep the last click is the fastest way to know whether the model fits your desk.

Frequently asked questions

Can recruiting assistants send emails on their own?

Many tools can; whether you should let them is a different question. The safe pattern is draft-for-approval: the assistant prepares the message and a recruiter sends it with one click. Auto-sending is defensible only for internal notifications. For anything a candidate receives, one wrong-record mistake costs more trust than the seconds an approval takes. Recruitifly's Fly always proposes outbound messages for confirmation.

What is human in the loop recruiting?

It means a person reviews and approves the consequential steps in an automated hiring workflow instead of letting software complete them end to end. The software gathers context, drafts and proposes; the recruiter decides. It is the practical form of the human oversight the EU AI Act expects from high-risk hiring tools, and it keeps accountability with a named person rather than a system.

Which ATS actions should require approval?

Anything a candidate sees or that changes their outcome: outreach and rejection emails, offers, interview invitations, and stage moves that trigger messages. Internal, reversible work such as logging calls, parsing CVs and setting reminders can run automatically, because a mistake there stays visible and fixable before it reaches anyone outside your team.

Does the EU AI Act require human oversight in hiring?

Yes. Tools that filter, rank or evaluate candidates are classified as high-risk, and the Act requires they be designed for effective human oversight: people who understand the system, can intervene or override it, and stay alert to automation bias. Employers and agencies deploying them must assign that oversight to someone competent. The high-risk obligations apply from 2 August 2026.

RE

Recruitifly Editorial

Editorial

Related reading

Want to see how this looks on your own data?

No hard promises. Just a straight conversation about exports, stages, and your current stack.

Contact us