In short
Human in the loop means an AI agent can prepare an action but a person must approve it before it happens. It belongs in front of anything irreversible or external: moving money, sending messages, changing permissions, deleting data. A good approval shows the exact change, the agent’s reason and the evidence it used; it is easy to decline, expires if ignored, is logged, and cannot be bypassed because the agent never holds the key that performs the action.
In the loop, on the loop, out of the loop
In the loop: the agent proposes, a person decides, then the action happens. On the loop: the agent acts and a person watches and can stop it. Out of the loop: the agent acts alone. Most businesses want agents in the loop for anything consequential, and out of the loop for reading and preparing work.
Which actions need a person
- Money: refunds, payouts, invoices, discounts, subscription changes.
- External communication: emails, messages and posts that reach customers or the public.
- Permissions: granting access, rotating keys, adding users.
- Deletion and anything else that cannot be undone.
- Anything above a value you set, even if smaller actions run on their own.
What a good approval looks like
- The exact change, not a summary: amount, recipient, object.
- Why the agent wants it, and what it read to get there.
- One deliberate action to approve, and one click to decline.
- An expiry, so forgotten proposals do not linger.
- A record of the proposal, the decision and the result.
- No way around it: the agent does not hold a key that could do the action directly.
Patterns that fail
Asking the model to double-check itself is not a control; the same model that made a mistake confirms it. Approvals in a chat window, mixed with everything else, get rubber-stamped. And a gate the agent can route around, because it also holds the real credentials, is decoration.
Checklist
Human-in-the-loop checklist
- We have listed which agent actions need a person’s approval.
- Approvals show the change, the reason and the evidence.
- The agent cannot perform approved-only actions itself.
- Unanswered proposals expire.
- Every proposal and decision is recorded.
The Human Queue, in MoltenRock Connect
Goldcote built this pattern into MoltenRock Connect. It is live for Stripe: agents propose refunds, invoices and more, you approve with Touch ID on your Mac, and only then does Connect send the change. Cloudflare is next.
Questions
Does human in the loop slow everything down?
Only for the actions that need it. Agents still read, research and prepare at full speed; the person spends seconds on a well-prepared decision.
Can we set thresholds?
Yes, that is a common pattern: small, reversible actions run on their own and larger ones wait. Start strict and loosen with evidence.
Is an approval in Slack or chat good enough?
It is better than nothing, but approvals mixed into conversation are easy to rubber-stamp and easy to spoof. A dedicated queue with the evidence attached works better.
What if the agent is wrong?
That is the point: the mistake stops at the proposal. Decline it, and the record helps you see why it happened.
More guides
- Private, safe AI for companies: a practical guide
- A simple shadow-AI policy for small businesses
- AI and client confidentiality: a practical guide for law and accounting firms
- AI agents and money: a refunds and disputes playbook
- Letting AI change your Cloudflare safely
- Secrets hygiene for AI agents: OpenClaw, Hermes and your API keys
- AI email triage without send access
- Solutions →