Human-in-the-Loop Best Practices
Ten practices for designing privilege rings, approval gates, kills, and escalation so human oversight stays real under production load.
Search across all documentation pages
Ten practices for designing privilege rings, approval gates, kills, and escalation so human oversight stays real under production load.
Use them as a design rubric and a PR checklist before agents gain side-effecting tools.
Items 1-10 are the core HITL design practices. Items 11-15 extend them into evidence and operations so the list stays useful after launch.
Hard-gate irreversible tools in a single dispatcher (practices 2 and 6). Everything else builds on a choke point that can pause.
They are framework-agnostic. LangGraph interrupts, AI SDK tool-approval states, and custom queues are mechanisms; rings and packets are the policy.
Yes when they can touch prod data, money, or customer messages. Internal does not mean low blast radius.
Widen safe auto-run (R0-R1), tighten packets for R2-R3, batch only similar low-medium items, and review queue metrics weekly.
High-value money movement, production deploys, broad permission changes, and any action your compliance policy already treats as dual-control for humans.
Fail closed for irreversible tools. Escalate to a secondary queue if you need coverage; do not treat silence as consent.
On the run detail page, in authenticated chatops, and in on-call CLI. Measure time-to-trip in drills.
Only for narrow, templated arg envelopes with strong monitoring - never as a blanket for open-ended tool args.
Audit answers who authorized which side effect. Analytics answers funnels and engagement. Keep access and retention appropriate to each.
Tools with side effects that have no ring label, or one allowlist where refunds and search share the same auto policy.
In the section sidebar as the close-out checklist, and from ADRs or runbooks that introduce new agent side effects.
Stack versions: Pins from the category manifest (verify at build): OpenRouter (~315+ models, July 2026 pricing/fees); LangGraph 1.0+; CrewAI 1.14+; Microsoft Agent Framework 1.0; Vercel AI SDK 6; Pydantic AI (latest); LlamaIndex (latest); OpenAI Agents SDK (latest + MCP); MCP (Linux Foundation governance); A2A (HTTP+SSE+JSON-RPC 2.0); Solana
@solana/web3.js+@solana/spl-token.
Reviewed by Chris St. John·Last updated Jul 16, 2026