MMarketing Against The Grain
← All frameworks
Innovation

Human-in-the-Loop Autonomy Ladder

Increase agent autonomy only as consequence, confidence, and trust allow.

Difficulty
Advanced
Time to result
~months to results
Steps
5
Confidence
95%

The autonomy ladder separates agent experiences by how much control remains with the human. At the lowest-risk level, the agent retrieves or summarizes information. It can then draft an action and ask the user to approve it, execute a preapproved bounded action while reporting completion, or operate without immediate review in narrowly trusted cases. Placement on the ladder depends on consequence, reversibility, confidence, sensitivity, and demonstrated reliability. Teams should begin with specific, low-risk use cases and expand autonomy as users build trust. This avoids treating agent UX as a binary choice between manual operation and unrestricted automation while still providing a path toward useful independent action.

Origin

Extracted from Marketing Against The Grain during a discussion of whether Siri should draft, display, confirm, or automatically send an email.

Core principles

  • 01Retrieval is safer than consequential action.
  • 02Approval requirements should reflect risk and reversibility.
  • 03Trust grows through narrow, successful use cases.
  • 04Users need visibility appropriate to the action's consequence.
  • 05Human oversight can decrease as reliability is demonstrated.

How to run it

  1. 1

    Classify the proposed action

    Assess its consequence, reversibility, sensitivity, and effect on other people or systems.

    Pro tip Use the highest-risk attribute to set the initial oversight level.

    Watch out A technically simple action can still have serious social consequences.

  2. 2

    Choose the lowest sufficient autonomy

    Start with retrieval, recommendation, or drafting before allowing execution.

    Pro tip Select the least autonomous mode that still removes meaningful user effort.

    Watch out Do not automate merely because an API makes execution possible.

  3. 3

    Design the approval experience

    Show what will happen, what information will be used, and what the user can change before approval.

    Pro tip Keep routine approvals brief while exposing details on demand.

    Watch out Approval fatigue can turn nominal oversight into automatic clicking.

  4. 4

    Make execution observable

    Confirm what the agent did and preserve an accessible record of the result.

    Pro tip Provide undo or correction paths whenever feasible.

    Watch out Silent action erodes trust when expectations and outcomes diverge.

  5. 5

    Expand autonomy through evidence

    Reduce oversight only after the agent performs a narrow use case reliably and users demonstrate comfort with it.

    Pro tip Expand one action class at a time.

    Watch out Reliability in one workflow does not establish reliability everywhere.

In the wild

Sending an airport update

The assistant detects that a flight is late and drafts an email to the user's siblings. Initially, it reads the draft aloud and asks whether it is acceptable to send. After repeated successful family updates, the user may authorize that narrow message type to send automatically.

Autonomy grows from drafting to bounded execution without beginning with unrestricted control.

Approving a customer refund

A support agent recommends a refund and shows the evidence to an employee. Small refunds within policy can later execute automatically, while unusual or high-value refunds continue to require approval.

Oversight remains proportional to financial consequence and policy uncertainty.

Common mistakes

Treating autonomy as all or nothing

Agents can occupy several useful levels between passive assistance and fully independent execution.

Using the same approval rule everywhere

Low-risk reversible actions and high-risk irreversible actions require different oversight.

Removing the human too early

Users need evidence from specific reliable workflows before trusting broader autonomous behavior.

Is it for you?

Best for

It is best for designers of agents that send messages, alter records, make purchases, or perform other user-facing actions.

Not ideal for

It is not ideal for purely informational tools that never create external effects.

From the transcript

Should I watch the agent do that? Should I get sign off on the email? Should I just know that it's done and get a…

Kieran Flanagan · 12:30

the use cases will either be human in the loop or like human completely out of the loop.

Kieran Flanagan · 13:30

the agents doing stuff on your behalf is going to be a massive behavior change amongst humans, probably gonna start with a couple very specific…

Kipp Bodnar · 13:00

From the episode

Apple Intelligence Can Outsmart 99% Of Marketers (WWDC Recap)