What is human-in-the-loop?
Last reviewed 7 October 2026
Human-in-the-loop (HITL) refers to a system in which a person takes an active part in the operation, supervision or decisions of an automated process at defined points. IBM frames it this way. For AI agents it usually means a run pauses before a chosen action, a named person approves, edits or rejects it, and the run continues from that decision.
Also called: HITL, human in the loop, human oversight, human approval step.
Why Human-in-the-loop (HITL) matters
Agents act, and some actions are expensive to undo: paying a supplier, emailing a customer, deleting a record, changing someone’s access. A human checkpoint before those actions turns an unrecoverable mistake into a rejected proposal. It also answers the question auditors and managers ask first: who decided this?
Regulation points the same way. IBM’s page quotes Article 14 of the EU AI Act, which requires high-risk AI systems to be designed so that natural persons can effectively oversee them while they are in use. Whether that article applies to you depends on your system and use case, and this page is not legal advice.
How it works
In machine learning, HITL has older meanings. IBM lists supervised learning, where people label training data; reinforcement learning from human feedback; and active learning, where a model asks for human input only on uncertain cases. These shape the model before it runs.
For agents, HITL happens at run time. The runtime intercepts a proposed tool call, saves the state of the run and shows the proposal to a person. LangChain’s human-in-the-loop middleware, for example, offers four responses: approve the call as proposed, edit its arguments, reject it with feedback to the agent, or respond with a message that stands in for the tool result. Saving state matters, because a person may answer hours later and the run must resume exactly where it stopped.
Protocols build it in too. The Model Context Protocol specification says hosts must obtain explicit user consent before invoking any tool. The design question is where to put checkpoints: too few and the agent acts unchecked, too many and people start approving without reading.
Example: a supplier bank detail change
A supplier emails asking to change their bank account. An agent reads the email, finds the supplier record and prepares the change. Because bank detail changes are a known fraud route, the workflow is set to pause at this point.
The approver, a named person in accounts payable, sees the proposed change, the original email and the sender address, plus a note from the agent that the domain differs slightly from the one on file. She rejects the change and asks the agent to request confirmation through the phone number already held on the record. The rejection, her name and the reason are stored with the run.
Two design choices made this work. The checkpoint sat before the irreversible action, not after it. And the approver saw the evidence, not a bare approve button.
How Swfte relates to it
Built in the product
Human approval is built into several parts of Swfte. In Swfte Studio, an approval step pauses a workflow run for a named person and continues on approve or reject. In Claude Code sessions run inside Swfte Cortex, any tool call beyond reading and searching files asks for approval first, and high-risk actions such as sending, paying, deleting, pushing code or running shell commands are held at a separate gate. Swfte Nexus can require approval for coding-agent actions under its policy.
These approvals are separate today and do not share one inbox. The platform also does not enforce separation of duties; you get it by choosing who is assigned to each gate. Swfte provides controls and evidence you can use in your own compliance work, and the posture depends on your use case and configuration.
Related terms
- Agentic workflow
An agentic workflow is a business process in which one or more steps are carried out by an AI agent that decides how to complete them, alongside fixed steps and human checkpoints.
- AI agent
An AI agent is a software program that uses an AI model to decide what to do next and then acts through tools to reach a goal it was given.
- AI governance
AI governance refers to the policies, roles, processes and technical controls an organisation uses to decide which AI systems it builds or buys, how they may behave, and who answers for them.
- Model Context Protocol (MCP)
The Model Context Protocol (MCP) is an open protocol that gives AI applications a standard way to connect to external tools, data sources and prompts, so one integration can work with any compatible client.
Common questions
- What is the difference between human-in-the-loop and human-on-the-loop?
- In human-in-the-loop designs, the system waits for a person at set points before it continues. In human-on-the-loop designs, the system acts on its own while a person monitors and can step in or stop it. Many agent deployments use both: approval for risky actions, monitoring for the rest.
- Which actions should require human approval?
- Actions that are hard to reverse or expensive if wrong: payments, changes to bank details, messages to customers or regulators, deletions, access changes and code deployments. Start with that list, then add actions that have caused problems before. Keep routine reads and drafts free of approval so reviewers stay attentive.
- Does human-in-the-loop slow everything down?
- Only at the checkpoints. The agent does the gathering and drafting, and the person makes one decision with the evidence in front of them. Runs pause while waiting, so set a timeout and decide what happens if nobody answers, such as escalating to a named fallback or rejecting by default.
- Is a human checkpoint enough to make an agent safe?
- No. People approve what they are shown, and rushed reviewers approve too much. Pair checkpoints with narrow tool permissions, step and spend limits, logging of every action and testing on real cases. Where the stakes justify it, make sure the person approving is not the person who asked for the action.
Sources
Definitions on this page were read on the sources below on 7 October 2026. Where sources define the term differently, the page says so. The full glossary lists more terms.
- IBM Think explainer defining human-in-the-loop (read 2026-10-07)
- LangChain documentation on human-in-the-loop middleware for agent tool calls (read 2026-10-07)
- Model Context Protocol specification, current version (read 2026-10-07)