Bounded autonomy and human intervention

A useful agent does not need unlimited rights.

What you will learn

  • Explain: a bounded agent loop
  • Apply the idea in an example: Bounded autonomy and human intervention
  • Recognize limitations and verify the exercise outcome

A useful agent does not need unlimited rights. Allow reading and drafting while retaining control over consequential actions.

This is a conceptual or external lab. It does not assume the application exposes every control described.

How it works, step by step

A bounded agent loop

An agent combines a model with tools, a goal and state. It observes the request, chooses a step, receives a result and decides whether to continue. A chatbot may only generate text; an agent may request an external action. Commercial definitions vary, so inspect actual control. Define success and stopping: a verified result, a maximum step count, repeated errors or an exhausted budget. Use narrow capabilities and minimal permissions. Useful autonomy means freedom within boundaries enforced by software.

Check access before use

Permissions must be enforced by servers and the data layer. Do not let the model decide whether a user may see a document. Filter sources before they enter context, not after generating the answer. Use minimal-access credentials, keep them out of prompts, screenshots and browser code, and rotate exposed keys. A widget domain allowlist does not replace API authentication. Authentication identifies you; authorization determines the operations and data you can use. Test denied access too.

Errors need explicit paths

A timeout differs from a permission error. Retry only transient errors, with bounded attempts and increasing delays. An operation with side effects may execute before its response is lost; retrying without an idempotency key can duplicate the effect. Streaming shows progress but does not guarantee completion. Checkpoints may allow failed stages to resume within runtime limits. Store the run identifier, stage, duration and error while removing secrets from logs. Measure slow paths as well as averages.

The visual map

Bounded autonomy and human intervention Follow the solid arrows for the main flow. Dashed blue arrows supply data or context; dashed pink arrows show feedback or returning results. Colors and shapes distinguish models, stores, decisions and outputs. Human approval is a conceptual integration control, not a built-in consequence of asking for approval in a prompt. Connections: User request → Agent / LLM; Agent / LLM → Choose next action; Human approves the action → External action; External action → Result to verify; Result to verify → Human verification; MCP tools / RAG → Result to verify; Access permissions → Choose next action; Step and iteration limits → Choose next action; Choose next action → MCP tools / RAG (Within allowed scope); Choose next action → Human approves the action (Consequential action); Human approves the action → Reject or stop (Denied); Human verification → Agent / LLM. A06 · Relationship map Bounded autonomy and human intervention Input User request Decision / control Access permissions Decision / control Step and iteration limits AI model / agent Agent / LLM Decision / control Choose next action Decision / control Human approves the action Tool / service MCP tools / RAG Output Reject or stop Tool / service External action Output Result to verify Decision / control Human verification Within allowed scope Consequential action Denied Main flow Data and context Feedback and return

Follow the solid arrows for the main flow. Dashed blue arrows supply data or context; dashed pink arrows show feedback or returning results. Colors and shapes distinguish models, stores, decisions and outputs. Human approval is a conceptual integration control, not a built-in consequence of asking for approval in a prompt. On smaller screens, scroll horizontally to follow the entire diagram.

A complete example

The agent proposes a return after checking policy. Its proposal includes order, reason and conditions. A refund is a separate operation requiring authorization and verification.

Try it yourself

  1. Classify operations as reading, drafting, reversible change and irreversible effect.
  2. Record the input, source and expected outcome before running the experiment. Use only the fictional data in the example.
  3. Follow the diagram stages. At every step record what information is received and produced; do not confuse intermediate output with the final outcome.
  4. Repeat after removing necessary information or making the input ambiguous. Check whether the system clarifies, stops or invents an answer.
  5. Compare with the explained solution. Keep the configuration, date, result and an explanation for differences. Change one thing and retest.

An explained solution

You obtain a verifiable proposal without automatic transactions or assumed persistent memory. A successful exercise lets you show the connection between input, stages and outcome. When information is missing, a cautious answer is more useful than invented details. Compare more than style: check conditions, sources and operations too.

When it helps and what can go wrong

A conceptual approval control does not establish its presence in the UI. Choose this approach when it improves a measured need. Keep a simple baseline and compare outcomes using identical inputs. One successful example does not establish reliability in every situation.

Check your understanding

Does more autonomy always give a better result?

No. It also increases room for errors, costs and unnecessary actions.

Why is removing a private source after answering too late?

The data has already entered model context and can be disclosed.

What outcome should this exercise produce?

You obtain a verifiable proposal without automatic transactions or assumed persistent memory.

Words to remember

  • Agent: A system that can choose steps and use tools toward a goal.
  • Autorizare / Authorization: Checking the right to access an operation or resource.
  • Idempotency: Controlled repetition without duplicating an effect.

Sources and your next step

To prepare: A05 — Web search and code execution