The human-control map for support automation
A governance model for deciding where people approve, monitor, interrupt, explain, and recover automated customer-support work.

“Human in the loop” sounds reassuring because it leaves the important noun undefined. Which human? In which loop? Looking at what evidence? With what authority? Before or after the customer is affected?
Generative assistance can produce substantial gains, especially for less-experienced workers—
in a major field study. The value is real. So is the need to design human control as an operating system rather than a disclaimer.
Map the automation chain
Draw each stage from customer intent to final state:
- intake and identity
- intent classification
- context retrieval
- answer or action selection
- policy and authority check
- execution
- customer communication
- logging and evidence
- monitoring and recovery
At each stage, record the model, deterministic rules, data sources, tools, owner, failure modes, and customer consequence. A single “AI agent” box hides the controls that matter.
Assign five human control jobs
Approve: a person authorizes a proposed action before execution. Use this for high-consequence, novel, or weakly evidenced work.
Monitor: a person reviews sampled or triggered outcomes after execution. Monitoring needs thresholds and a response path; a dashboard nobody owns is not a control.
Interrupt: a person or automated circuit breaker can stop the system during an incident, drift, unsafe behavior, or tool failure.
Explain: an accountable owner can reconstruct the sources, policy, action, and reason well enough to answer a customer challenge.
Recover: somebody can reverse or remediate the outcome, restore access, correct records, communicate, and learn from the failure.
Different roles can hold these jobs. Every material automation needs all five assigned.
Choose control by consequence
Use four bands. Low-consequence, reversible answers may run with monitoring. Material account changes require stronger evidence and selective approval. Sensitive decisions involving identity, privacy, security, vulnerability, eligibility, or legal rights need explicit authority and a reliable human path. Critical actions may be unsuitable for autonomous execution at all.
Do not set autonomy from model confidence alone. Confidence can be poorly calibrated, and a highly confident wrong refund denial still harms the customer. Combine evidence quality, novelty, reversibility, value, affected population, and consequence.
The human-in-the-loop definition provides the shared vocabulary; the AI vendor scorecard helps test whether a product exposes the controls.
Design the handoff as a product
When automation exits, carry the customer goal, identity state, transcript or faithful summary, sources retrieved, actions attempted, tool results, policy applied, reason for exit, and current promise. The receiving person should see this before greeting the customer.