From LinkedIn · · 1 min
Human in the loop is a box on a diagram
The log shows an approval. It doesn't prove a decision was made. A real control leaves evidence of disagreement, and most of them never have.
By Olha Shevchenko. Audits production systems on AWS and Node.js.
The audit log says:
AI recommendation: approve. Human review: approved.
So the human control worked. Apparently.
The log shows an approval. It doesn't prove a decision was made. It doesn't show what evidence the reviewer saw, how much time they had, whether conflicting signals were visible, or whether escalating one case would block the whole queue.
This is the dangerous middle: formally advisory, operationally decisive.
The model recommends. A reviewer approves. But if the output arrives with an authoritative explanation inside a crowded queue, the human is part of the interface, not the control. An expensive checkbox with a name.
I separate four states: designed, instrumented, exercised, effective. Workflow definitions and permissions show that review was designed. Logs show it was instrumented. Sampled cases with real interventions show it was exercised. Effective is harder.
A real control leaves evidence of disagreement. Someone rejected, changed, or escalated the recommendation, recorded why, and the downstream system followed the human decision.
Where that cannot be established before close, the answer is not "control passed." It is a validation item: replay the decision with its original context, exercise the escalation and stop paths, name the owner, and price the work.
"Human in the loop" is a box on an architecture diagram.
A person who can change what happens is a control.