How to choose a human-in-the-loop app for AI agents
A human-in-the-loop (HITL) app puts a person's decision in the middle of an automated workflow: the agent pauses, a phone buzzes, someone says yes or no. There are a growing number of them. Before one gates your agent's payments, deploys or data access, ask it these seven questions.
-
Does the request reach a person fast, and read plainly?
An approval nobody sees in time is a stalled workflow. Look for push notifications on the phone people already carry, and a request written in plain language — what the agent wants to do, to what, for how much — not a JSON blob.
-
Does the approver see the exact action?
A summary like “send payment” is not the same as “wire $52,400 to vendor-payouts”. Every parameter that changes the outcome should be on the screen before the decision.
-
Is the decision tied to a person, or to an unlocked phone?
If anyone holding an unlocked phone can tap approve, the record says less than it seems to. A biometric at the moment of approval, and a signing key generated on the device, tie the decision to the person enrolled on it.
-
Can your backend tell a real approval from a forged one?
This is the question most HITL tools skip. If the approval arrives as a webhook that is believed because its URL is secret, anyone who learns the URL can approve anything. Ask what the approval message is signed with, and who holds the key.
-
Is the approval bound to the action it approved?
An approval for “refund $40” must not be reusable for “refund $4,000”. A hash of the action inside the signed approval makes any edit fail verification, and a one-time identifier stops the same approval being replayed.
-
Can you prove it later, without the vendor?
Months later an auditor, a client or a court asks who approved this. A row in a vendor's database is an assertion; a signed receipt you can verify offline with an open-source tool is evidence. It also keeps the vendor's uptime out of your execution path.
-
What happens when nobody answers — or several people must?
Silence should mean no: requests should expire, never default to yes. For the large actions you will want a quorum, two of three or any N of M, ideally with votes hidden until the request resolves so nobody simply follows the first answer.
Where HumanAuth stands
We built HumanAuth around questions four to six, because they are the ones a pause-and-ping tool cannot answer. Requests arrive by push on iPhone, Android and the Mac menu bar. Every approval takes a biometric and is signed by a key that never leaves the device, countersigned by the platform, and bound to a hash of the exact action. Your backend verifies the receipt offline with an open-source verifier and burns it after one use. Requests expire; groups can require a quorum with blind ballots.
Where it does less: decisions are approve or deny with a reason, not ratings or free-form answers, and there is no native Make or Zapier module yet. We have compared it line by line with HITL.sh, sources included.