# Human-in-the-Loop Automation with n8n

Liam McGarrigle, n8n | AI Engineer Europe 2026 | 1:19:22

Source: https://www.youtube.com/watch?v=tDArkCqjA-c
Channel: AI Engineer (https://www.youtube.com/@aiDotEngineer). Summarised by AIE Talks.
Page: https://aietalks.com/talks/human-in-the-loop-automation-with-n8n
Published: 2026-05-02
Tags: guardrails, human-in-the-loop, observability, workflows

## TL;DR
- n8n lets teams build AI workflows visually while inspecting executions, changing tool inputs, and controlling access to credentials.
- Human review can intercept sensitive actions such as sending email or creating calendar events, so an agent cannot call those tools without approval.
- A working agent can later be extended with Slack, scheduled runs, persistent memory, sub-workflows, REST APIs, and specialized subagents.

## Summary
Liam McGarrigle builds a Gmail and Google Calendar agent in n8n from an empty workflow. He starts with a chat trigger, connects an AI agent to a language model, adds memory, and exposes Gmail and Calendar operations as tools. Much of the workshop focuses on control. Tool names and descriptions guide the model, individual fields limit what it can change, project permissions control credential access, and execution logs show the inputs and outputs of each step. Sensitive tools can pause for human approval in the chat interface. McGarrigle also explains the settings needed for approval messages, including changing the chat trigger to use response nodes. He then shows how the same workflow can run through Slack or on a schedule. For larger systems, he recommends sub-workflows and specialized subagents rather than putting every tool into one agent. The examples are practical, and he is candid about places where n8n still requires custom workflow design.

## Key ideas
### n8n makes agent workflows inspectable and editable
[02:33](https://www.youtube.com/watch?v=tDArkCqjA-c&t=153s)
McGarrigle argues that building an agent is easy, while knowing what it did, seeing failures, and changing its behavior is harder. He presents n8n as a visual agent builder and orchestrator where the workflow remains visible. The platform began as a low-code integration tool before chat-based AI became popular. A workflow still consists of triggers, actions, and control flow. Triggers can include forms, schedules, webhooks, API calls, and chat. Actions call services such as Gmail, Google Contacts, or Salesforce. Developers can stay in the visual editor, then add JavaScript inside individual fields when they need more control.

### A chat trigger and memory turn an agent into a usable conversation
[12:00](https://www.youtube.com/watch?v=tDArkCqjA-c&t=720s)
The workshop uses n8n's built-in chat trigger because it is already available for testing. The trigger can also be replaced with Slack events later. Publishing the workflow and enabling it in Chat Hub provides a chat interface inside n8n. McGarrigle then connects an AI Agent node to a language model through OpenRouter. The first agent can answer a message, but it cannot recall an earlier message until memory is connected. Simple Memory stores the conversation in n8n and uses the session ID from the chat trigger. The context window controls how many prior messages are included, while PostgreSQL or Redis can store messages for an existing application.

### Tools should expose only the fields an agent is allowed to set
[21:40](https://www.youtube.com/watch?v=tDArkCqjA-c&t=1300s)
Gmail and Google Calendar nodes can be connected to the agent as tools. Unlike giving an agent broad access to an API, each n8n tool exposes individual fields. The workflow author can allow the model to set the subject, message, and recipient while leaving other fields fixed. This limits what the model can change, although it also means every needed field must be configured. Expressions can combine static text with values from the trigger or other nodes. McGarrigle uses this to build templates such as an AI response to a specific chat message.

### Tool names and descriptions are part of the agent's prompt
[29:06](https://www.youtube.com/watch?v=tDArkCqjA-c&t=1746s)
The agent sees each tool through its node name and description. McGarrigle recommends renaming nodes clearly and writing tool descriptions manually instead of relying on automatically generated text. Descriptions can explain when a tool should be used and clarify confusing fields. For Google Calendar, the API field named 'summary' means the event title, so the description should say that directly. The field's generated key can also be changed from 'summary' to 'title'. Field-level descriptions provide another place to correct model mistakes, such as passing a message ID where a thread ID is required.

### Human review can block sensitive actions before they run
[41:12](https://www.youtube.com/watch?v=tDArkCqjA-c&t=2472s)
McGarrigle adds human review to actions such as sending email, replying to email, and creating calendar events. The review node pauses the workflow and presents the proposed action in n8n's chat interface. An approver can send or decline it, and leaving user input enabled means a written response can deny the request. The agent calls the tool as usual, while n8n intercepts the call before execution. A useful approval message should show the recipient, subject, and message rather than only saying that a tool was requested. The same review layer can cover multiple tools, although each tool may need different parameters in the displayed message.

### Approval workflows need response nodes and clear execution logs
[43:01](https://www.youtube.com/watch?v=tDArkCqjA-c&t=2581s)
When the approval step initially fails, the error explains that the chat trigger must use the 'using response nodes' mode instead of streaming. In that mode, chat responses are controlled by explicit chat nodes, including the human review message and the final response. The result arrives as one message rather than a stream. The Executions view records each run, including the tool input, output, waiting state, and later completion. McGarrigle uses an execution copied back into the editor to inspect badly formatted calendar dates, then fixes them with n8n expressions and Luxon date formatting.

### The same controlled agent can run from Slack or on a schedule
[1:04:04](https://www.youtube.com/watch?v=tDArkCqjA-c&t=3844s)
After the Chat Hub demo, McGarrigle shows how to replace the chat trigger and response with Slack nodes. A Slack workflow can post a loading animation while the agent works, then remove it after the response. A schedule trigger can run the agent every hour without a person initiating each run. The workflow can still send proposed actions to Slack for review. McGarrigle describes using this pattern for GitHub issues or pull requests, where the agent scans code and drafts messages but does not contact colleagues or clients until he has seen the result. The workshop document also contains instructions for persistent memory and autonomous scheduled runs.

### Subagents and sub-workflows keep larger systems manageable
[1:16:41](https://www.youtube.com/watch?v=tDArkCqjA-c&t=4601s)
McGarrigle recommends using specialized subagents when an automation needs many tools. The demonstrated agent can become an email and calendar subagent, while other agents handle GitHub issues or Jira. A parent agent can call these specialized agents, which reduces the context each one receives and allows each to use a model suited to its task. Sub-workflows also provide a way to implement approval logic outside n8n's built-in human review node. For a phone interaction without approval buttons, a sub-workflow can ask for confirmation, return true or false, and branch with an If node. n8n workflows can also expose REST APIs through webhook triggers for use by other systems.

## Notable quotes
- "One of the problems we're seeing and where the winners are going to lie is seeing what your agent can do, knowing what it's doing, seeing what went wrong and being able to tweak it and fix it." (02:33)
- "It can only set the things that we tell it to specifically." (26:23)
- "It just cannot get past this layer. It can't use this tool without going through this chat." (41:57)
- "I don't want AI to message co-workers or clients or anything without seeing it first." (1:06:49)
- "Use the sub agent tool, agent, and then you can have one agent that calls other specialized agents." (1:16:41)

## Tools & references mentioned
- n8n
- Gmail
- Google Calendar
- Slack
- OpenRouter
- Sonnet 4.6
- ChatGPT 5.3
- Claude 4.6
- PostgreSQL
- Redis
- GitHub
- Jira
- MCP
- Cloud Code
- Luxon

## Who should watch
- You are building an AI workflow that can send messages, change calendars, or modify business data, and you need a review step before those actions run.
- Your team wants a visual starting point for an agent but still needs JavaScript, field-level restrictions, credential permissions, and execution logs.
- You want to move an interactive agent into Slack, scheduled jobs, REST APIs, or a larger system made from sub-workflows and specialized agents.

## Editor's note

Liam McGarrigle uses a copied execution to inspect badly formatted calendar dates, then fixes them with n8n expressions and Luxon date formatting. Kitaru records every model call and tool result from a real run, then replays the agent against those same inputs and responses, so the date-handling change can be tested without touching Google Calendar.

Written by the AIE Talks editors (the Kitaru team), not by the speaker.

## Related talks

- [How I automate my own job at Hugging Face using agents](https://aietalks.com/talks/how-i-automate-my-own-job-at-hugging-face-using-agents) (Niels Rogge, Hugging Face, 20:37)
- [Realtime multiplayer, automation, and you!](https://aietalks.com/talks/realtime-multiplayer-automation-and-you) (Idan Gazit, GitHub, 21:41)
- [The Human Is an Async API](https://aietalks.com/talks/the-human-is-an-async-api) (Melanie Warrick, Temporal, 19:16)
- [Conquering Agent Chaos](https://aietalks.com/talks/conquering-agent-chaos) (Rick Blalock, Agentuity, 14:40)
- [Paperclip: Open Source Human Control Plane for AI Labor](https://aietalks.com/talks/paperclip-open-source-human-control-plane-for-ai-labor) (Dotta Bippa, Paperclip, 24:34)
