Back to the blog

Human gates: a field guide

AgentsGovernancePractice

The question we get most often about agents is some version of "how do we keep a human in the loop?" It is the right instinct and the wrong framing. The useful question is which loop, and where.

Put a person on every action and you have built a very expensive form with extra steps; nobody will keep approving, and the agent will be turned off or rubber-stamped. Put a person on no actions and you have handed a credit card to a process that does not know what it does not know. The craft is in the placement.

Gate on consequence, not on confidence

The wrong way to place gates is by how confident the model claims to be. Confidence scores are useful signals but they are not the axis that matters.

The right axis is consequence. Ask of each action the agent can take: if this is wrong, what does it cost to undo, and who pays?

Drafting an internal summary that a person will read anyway: low consequence, no gate. Filing a ticket in your own tracker: low consequence, reversible, no gate. Sending an email to a customer: moderate consequence, hard to unsend, gate it until trust is established. Issuing a refund, changing a record of legal or financial weight, contacting someone outside the company on your behalf: high consequence, gate it, probably permanently.

Write this down as a table before you build anything. Every action, its blast radius, its reversibility, and the gate decision. That table is the beginning of your governance policy, and it is also the specification for the agent.

Three kinds of gate

Not all gates are the same, and using the heavy one everywhere is the second most common mistake.

The approval gate stops the agent and waits for a yes. Use it for irreversible or external actions. Design the approval so it takes seconds: show the person what will happen, what it is based on, and one button.

The review window lets the action proceed after a delay unless a person intervenes. Good for medium-consequence actions with a natural pause, like scheduled sends. The agent queues the email for twenty minutes; the person can pull it back. Most of the time nobody does, and that is the point.

The sampling gate lets the agent act freely but routes a percentage of actions to a person for after-the-fact review. This is how you keep an eye on low-consequence, high-volume work without paying attention to all of it. It is also how you build the evidence to relax the heavier gates later.

Gates should loosen as evidence accumulates

A gate placed on day one is a hypothesis about risk. Keep the data on how often the person overrides the agent at that gate. If a gate has been approved a thousand times and overridden twice, it is not protecting anything; it is training people to click yes. Downgrade it to a review window or a sampling gate.

If a gate is being overridden often, that is not a gating problem. It is an agent problem. Fix the behaviour, not the approval flow.

This is the practical reason the audit trail matters. Without a record of what the agent proposed and what the person did with it, you cannot make these decisions with anything but anecdote.

The gate that is not a button

The most important gate is not in the workflow at all. It is the rule that the agent queues a question rather than guessing when it is uncertain. An agent that asks is an agent that can be trusted with more. An agent that fills the gap with its best guess will eventually fill it with a confident, wrong, expensive one.

Build the ask path first. Make it cheap for the agent to say "I do not know what to do here" and cheap for a person to answer. Most of what looks like a need for heavy approval gates is actually a need for a good question channel.

A short checklist

Every action inventoried, with consequence and reversibility written down. Approval gates only where undoing is hard or the action leaves the building. Review windows where a pause is natural. Sampling where the volume is high and the stakes are low. Override rates tracked, and gates adjusted on evidence. A question channel that the agent uses before it guesses.

Get those six right and "human in the loop" stops being a slogan and becomes a design.

Tell us where AI is stuck.

One conversation — we’ll tell you if we can help, and what we’d do first.

Book a call