The authority boundary is becoming part of the implementation.
“Human in the loop” is becoming one of those phrases that sound more precise than they are.
A human doing what?
Reviewing an output? Approving an action? Checking evidence? Signing off on a safety decision? Taking responsibility when something goes wrong?
In our recent conversations with operators putting AI into real workflows, there was no common rule for where humans should remain involved.
There was, however, a pattern worth examining.
In several of the clearest cases, the authority boundary became more explicit as the consequence of the action increased.
At Call Force Global, Miki Furman uses AI to extend quality monitoring across customer calls. The technology can review and flag far more interactions than a traditional sampling process.
But the final coaching and QA decision remains human.
Furman described the distinction as:
“Separate coverage from authority.”
That is a useful way to think about AI beyond customer service.
A system can see more without necessarily receiving the right to decide more. Joel Goldstein described a similar boundary at Mr. Checkout, where AI classifies incoming brands, checks disqualifiers and prepares a distributor-routing recommendation. The referral itself remains a human decision:
“It prepares, a human commits.”
More capability does not automatically mean more authority
The distinction becomes sharper when an AI output can materially affect people, money or safety.
Rohit Shinde, a senior process engineer at Atlas Prediction Control, described AI being used to identify possible engineering failures and compare findings against technical standards.
The system can expand the amount of information an engineer can inspect.
It does not sign the result.
“The engineer signs and the system does not.”
That may sound obvious in process engineering, where an incorrect decision can have severe consequences.
But the same question is beginning to appear in much less obvious workflows.
At Karo, founder Anik Devaughn described the operating principle as:
“Automate the work, never the approval.”
Devaughn’s example is useful because the organization automates aggressively while still protecting specific approval points.
The organization can automate preparation, production, and execution while deliberately protecting particular approval points.
The line often appears where the action changes something outside the system
Patrick Gibbs, founder of Epiphany Dynamics, draws the boundary around what an agent is allowed to touch.
Reading information and drafting work sit on one side.
Sending messages, changing a system of record, or taking an external action sit on the other.
His public writing on agent permissions makes the same point: once AI moves beyond answering questions and starts acting through files, APIs, email, or business systems, permission design becomes part of the implementation.
This is where the current AI discussion can become misleading.
“Autonomous” makes it sound as if there are only two options:
AI acts independently.
Or a human approves everything.
Real workflows are becoming more granular than that.
An AI system might be allowed to:
- read customer history
- prepare a response
- classify the request
- recommend an action
- update an internal field
while still requiring approval before it:
- sends something externally
- changes a financial commitment
- modifies an authoritative record
- affects an employee
- makes an irreversible decision
Permission can be designed at the level of specific actions.
What can the system read, prepare, recommend, change, send, or commit without approval?
Research has an authority problem too
The same issue appears before a decision is made.
Fırat Mıhcı, founder of HumanizeMyAI, described a research workflow in which AI can gather, classify, and organize considerably more information than a person could manually review.
But the system does not get to decide that what it found should be accepted as evidence.
His rule:
“AI may propose candidate evidence; it cannot promote itself into evidence.”
That distinction matters well beyond research teams.
AI can now produce an answer and provide sources alongside it.
Those are separate claims.
Someone may still need to verify whether:
- the source actually supports the statement
- the source is credible
- the methodology is appropriate
- contradictory evidence exists
- the conclusion follows from the evidence
As AI increases the amount of information an organization can process, verification becomes part of the question of authority.
Who decides what the organization is willing to believe?
“Human in the loop” needs a job description
Across these conversations, the useful distinction was not human versus AI.
It was the role each was being given.
| AI can… | The unresolved management question |
|---|---|
| Observe information | What is it allowed to access? |
| Prepare work | Who checks whether the preparation is reliable? |
| Recommend an action | Who decides whether to follow it? |
| Execute an action | What is it allowed to change without approval? |
| Commit resources or affect people | Who has actual authority? |
| Influence consequential decisions | Who owns the outcome? |
There is no reason every workflow should stop at the same point.
A reversible internal action may deserve very little friction.
A safety decision, personnel action, financial commitment, or external representation may deserve considerably more.
The important part is that the boundary is intentional.
This is becoming an operating-design question
The first generation of enterprise AI mostly created outputs for people.
The next generation increasingly has access to tools.
It can update records, contact customers, trigger workflows, allocate resources, and initiate actions.
That changes the implementation question.
Companies will still need to ask whether the AI performs well enough.
But they also need to decide:
- What can the system see?
- What can it recommend?
- What can it change?
- What requires approval?
- Who can override it?
- Who answers for the result?
Those decisions should probably happen before an agent is given broader access, not after something goes wrong.
The operators we spoke with are drawing those lines in different places. That’s exactly what we should expect.
The consequences of a QA flag differ from those of an engineering sign-off. A draft is different from an external action. Finding evidence is different from accepting it.
Across these cases, the more useful question is where the organization places human authority, and why.
If your AI implementation is moving from generating work to acting on it, that boundary is worth making explicit before you scale it.
Working through that decision? Email us.
Sources and Contributors
The observations and quotations in this article come from Praxable’s August 2026 operator research on AI inside real workflows.
- Miki Furman — Call Force Global
- Rohit Shinde — professional profile / Atlas Prediction Control
- Anik Devaughn — Karo
- Patrick Gibbs — Epiphany Dynamics
- Fırat Mıhcı — HumanizeMyAI
- Joel Goldstein — Mr. Checkout

