Human-in-the-loop (HITL)
Also: 人工確認 · 人工審核 · 人在迴路 · HITL
A deliberately inserted point where the flow stops and waits for a human: the agent continues only after a person has looked and approved.
When you will meet it
You need it the moment agents do irreversible things — transfers, sends, deletions, deployments. Failure runs both ways: no human anywhere and one hallucination can cause unrecoverable loss; a human everywhere and the automation is dead, with you as a full-time approve-button clerk. Placement matters more than quantity.
An analogy
Like dual authorisation at a bank: small transfers go through at the teller's desk; large ones need a supervisor's countersignature. The supervisor does not sit behind every counter — the queue would reach the street — and appears only above a threshold.
Minimal example
該停的點(示意):
· 不可逆動作前:rm -rf、DROP TABLE、git push --force
· 花錢動作前:呼叫付費 API 超過預算門檻、下訂單
· 對外發送前:郵件、訊息、發布文章
· 權限升級前:從唯讀切到可寫、從沙箱切到主機
不該停的點:
· 讀檔案、跑測試、grep —— 可逆且低成本的動作
· 每個工具呼叫都問 → 用戶開始無腦按同意,確認失去意義Note the last line: approval fatigue is a real failure mode. Once agree becomes a reflex, the control exists in name only — so human checkpoints must be few and precise, placed right before the most expensive cut.
What people get wrong
- Counting notification as approval. A notification informs after the fact; an approval gate blocks before it. A message sent after the action is not human-in-the-loop — it is incident reporting.
- Assuming HITL settles everything. If what the human sees is the agent's own summary, the human is merely endorsing the agent's narration; in high-risk cases show the raw action — the exact command, recipient and amount — not a digest.