What human in the loop means for AI agents
Human in the loop is not a setting. Where the loop belongs for an AI agent, what makes a checkpoint real, and why silence must never count as a yes.

The phrase is on every agent product now, including ours. It usually means that a person is involved somewhere in the process, which is not a specification and certainly not a safety property. Here is what we think it has to mean before it is worth printing on a page.
A definition that survives contact with a real account
Human in the loop means a person reviews and approves what a system is about to do, before it takes effect. For an AI agent that is a checkpoint: the agent prepares the exact action, such as an email, a refund or a published post, then stops and waits for someone to approve it, change it or reject it. If nothing can stop the action once it has been prepared, there is no loop. There is a log.
The term comes from machine learning, where a person labels or corrects the cases a model is unsure about. Agents borrowed the phrase and quietly dropped the part that made it useful, which was that the human's answer arrived before the output counted for anything.
Three places the loop can sit
Agent products put the person in one of three positions. They are not equivalent, and the marketing language rarely distinguishes them.
- Before the run. You approve the brief, then the agent runs to completion. This is a hand-off, not a loop: the review happens at the moment you know the least, before the agent has read anything or discovered that your instructions were ambiguous.
- Between the steps. You approve the plan. Better, but a plan is a statement of intent, and the distance between an intended step and the payload it eventually produces is exactly where things go wrong.
- Before the action leaves. You approve the actual payload: this recipient, this amount, this wording, now. Only the third position bounds what can go wrong, because it is the only one where the thing being approved is the thing that happens.
What makes a checkpoint real
A checkpoint that exists technically but is useless in practice is the common failure. Four properties separate the two.
- The exact action, not a summary of it. The tool that will be called and the payload it will send, rendered so a person can read it in seconds. A summary is a second model output standing between you and the thing you are approving.
- The cost, before you agree to it. What the run has spent, and what this step adds. An approval you cannot price is a signature on a blank line.
- A deadline with an escalation behind it. Work does not wait politely forever, and neither should the queue. The deadline has to lead somewhere other than the action going ahead.
- A record of what the decider saw. Not only who clicked, but the version of the payload in front of them, stored with the decision so a disagreement three months later has an answer.
In Delagents those are the four fields on every card in the approvals inbox, and each decision is written to an append-only log under the name of the person who made it.
Silence is never a yes
The most tempting shortcut in any approval system is the timeout that approves. It makes the product feel fast, it makes the demo smooth, and it quietly converts every holiday, every sick day and every busy afternoon into consent. Once that rule exists, the loop is decorative: the default outcome is the action, and the person is an optional brake.
In Delagents a checkpoint left past its deadline escalates to the next approver. If nobody answers, the delegation pauses, and a request expires after seven days. Nothing is ever sent because somebody was away from their desk.
A loop that asks about everything is a loop nobody reads
The opposite failure is just as fatal and much more common. If every read, every search and every draft needs a click, people start approving in bulk without looking, usually within a week. You have not built oversight. You have built a rubber stamp with extra steps, and it now carries the authority of a process.
So the line has to sit somewhere defensible. Ours: inside the workspace an agent reads, searches, drafts and organises freely, because none of that is visible to anyone outside and all of it is reversible. Anything that leaves the workspace waits for a person.
Under that line sits a floor of eight actions that no policy can loosen, not even by an owner: a first message to someone outside the workspace, moving money, deleting records it did not create, changing permissions, connecting an integration, signing or buying, publishing, and acting in another workspace. The reasoning for each one is in checkpoints and the floor and in eight things an agent never does without a person.
The questions to ask any product that uses the phrase
Three of them, and they are answerable in a trial afternoon.
- Which position does the person occupy: the brief, the plan, or the action itself?
- What exactly are they shown at that moment, and does it include the cost?
- What happens when they do not answer: does the action go ahead, or does the work stop and wait?
A product that answers those clearly is making a real claim. A product that answers them with the phrase itself is describing a hope.
Every new agent's first run in Delagents is draft-only, whatever its instructions say. Write access unlocks after a person has reviewed one complete delegation.
Delagents is the private office for your AI staff. Start delegating, or see how sign-off works.


