Concept · Chapter 13: Agents
Human-in-the-Loop Agents
Human-in-the-loop systems reserve meaningful decisions or approvals for a person at defined points in execution.
The problem
Some actions require judgment or authority the model does not have.
The solution
Present the exact proposed operation and obtain a decision before that operation executes.
The consequence
Oversight works only if the person can understand and change the outcome.
You should understand first
- Text as Data
- Probability and Distributions
- Conditional Probability and Bayes' Theorem
- Probability of Sequences
- Language Modeling
- Vectors
- Dot Product
- Embeddings
- Attention
- Softmax
- Self-Attention
- Causal Masking
- Entropy
- Loss Functions
- Cross-Entropy Loss
- Autoregressive Next-Token Prediction
- Pretraining at Scale
- GPT-1 → GPT-2 → GPT-3
- In-Context Learning
- The Turing Test
- Symbolic AI
- Logic and Rules
- Expert Systems
- Knowledge Representation
- The Knowledge-Acquisition Bottleneck
- From Rules to Learning
- Supervised, Unsupervised and Self-Supervised Learning
- Expected Value and Variance
- Reinforcement Learning
- MDPs, Policies and Value
- Decoding: Greedy, Temperature, Top-k, Top-p
- One-Hot Encoding
- Tokenization
- Chat Templates
- System Prompts and Instructions
- Structured Outputs and Constrained Decoding
- Tool Calling
- LLM Agents
- Agent Runtime
- Human-in-the-Loop Agents
Make the decision concrete
A useful approval names the operation, affected resource and consequence. “Approve changes?” hides the information needed to judge them. Approval of one patch should not silently cover a different patch or deployment.
The runtime records the scope of the decision and checks it at execution. If the proposal changes, the old approval may no longer apply. External tool output cannot impersonate a user's grant of permission.
Human attention is finite
Ask at consequential boundaries rather than generating a confirmation for every harmless read. Ambiguous objectives may require clarification; repeated unexplained failures may require a handoff. In either case, preserve the evidence and state so the person is not forced to reconstruct the whole run.
Try it · toy model
A planted line in a bug report tells the agent to leak a secret. Choose the runtime's rules, approve or deny writes as the run pauses for you, and see what leaked, what got fixed and what changed that shouldn't have.
The checkbox in this simulation models approval for one exact write. Changing the proposal clears it. It does not demonstrate a production authentication system.
What to remember
- Human-in-the-loop systems reserve meaningful decisions or approvals for a person at defined points in execution.
- Present the exact proposed operation and obtain a decision before that operation executes.
- Oversight works only if the person can understand and change the outcome.