So basically, all traffic is directed through the IPS, which can then block or allow the packets based on policy. It can also perform a level of correction or modification if required.
An IDS on the other hand is purely a monitoring device; it cannot act directly on anything it detects. Typically connected via network tap or a span port on a switch / router it sees a copy of a traffic but does not interact with it. You rely on humans usually in a 24×7 Security Operations Center (SOC) to monitor the alerts, investigate and take appropriate action.