Gate what can't be undone, escalate on a threshold you chose deliberately, review async, and absorb corrections without restarting.
Deciding where a person has to say yes. Not everywhere — that's unusable — but at every step that can't be taken back.
It's what makes an agent shippable in a real business, and the design question is where the gate goes, not whether.
Human-in-the-loop is not a fallback for a weak agent; it's how autonomy stays affordable. The design has four parts. Approval gates: identify the actions you cannot undo in one click — money moving, messages sent, data deleted, code deployed — and halt there with the diff, not the prompt. Escalation thresholds: pick where confidence, value or missing evidence tips a run to a human, knowing that raising the bar trades human load against errors reaching users. Review mode: blocking review leaves the agent idle for hours, so checkpoint the decision into a durable queue and keep working on what doesn't depend on it. And interrupts: a mid-run correction should be absorbed as a new observation, never force a restart.
I gate on reversibility, not confidence: if I can't undo it in one click — money moving, a message sent, data deleted, code deployed — a human decides. The approval surface shows the diff, the amount and the policy cited rather than the raw prompt, and on approve the run resumes from a checkpoint instead of restarting. Escalation uses a threshold I chose per action class, knowing that raising it cuts errors reaching users but raises review load. Reviews are async: checkpoint the decision into a durable queue and keep working on independent steps, so one human batches twenty approvals. And a mid-run correction is appended as a high-priority observation — absorb it, don't cancel the run.
Why AI Agents Need A Human in the Loop Now — IBM Technology, 7:27