Six controls turn "a human is in the loop" from an intention into a designed, recorded property of the system.
Review thresholds
Where AI output stops and waits
Defined points at which output pauses for a person, set by risk and by output type. What proceeds automatically and what is held is a deliberate decision, not a default.
Escalation
When something exceeds authority
Clear paths for when work exceeds an agent's authority, confidence, or scope: who it goes to, on what trigger, and what happens while it waits. Designed, not improvised at the moment of failure.
Approval gates
Sign-off before it takes effect
Required human approval before a consequential action proceeds. The gate names who can approve, what they are approving, and the ability to hold, override, or halt.
Role-based permissions
Authority bounded by role
Who can configure, who can approve, who can override, and who can only view. People act within defined permissions, and those permissions are part of the system's design.
Audit trails
A record that can be examined
What the AI did, what was reviewed, what was approved or overridden, when, and on whose authority — recorded so the work can be reconstructed and stood behind.
Sensitive-output review
Held before it leaves the system
Outputs that touch sensitive data, individuals, or regulated material are routed to human review before release — regardless of the automation tier they originated in.