Governance
Human gates that scale
Approval fatigue is a design flaw. Where human judgment actually belongs in an agent pipeline.
Ask a room of engineers where humans belong in an automated pipeline and you will get one of two answers. Either "at every significant step," which does not scale, or "only when the system is unsure," which assumes the system knows when it is unsure. Both are wrong, and the second is dangerous.
Approval fatigue is a design flaw
Put a human gate on every change and within a month the human is a rubber stamp. This is not a failure of diligence. It is arithmetic. Attention is finite; the number of approvals is not. A reviewer facing forty approvals a day gives each one ninety seconds, and ninety seconds of attention on a change you did not write is indistinguishable from no attention at all — except that it produces a signature that says otherwise.
That signature is worse than useless. It converts an unreviewed change into a change with documented approval, which is exactly the artifact an audit will accept and a post-incident review will find embarrassing.
Two axes, four answers
The framework we use is deliberately crude, because crude frameworks get applied and subtle ones do not. Score the action on two axes: stakes (what does it cost if this is wrong) and reversibility (how hard is it to undo).
Low stakes, reversible. Full automation, sampled review. Let the system act and audit a random sample to catch drift. Drafting internal summaries, tagging tickets, formatting data. Putting a human in this loop is where your review budget goes to die.
Low stakes, irreversible. Automate, but log richly and alert on anomalies. The cost of any single mistake is low; the cost of a systematic one compounds silently. Sending a notification is the canonical case.
High stakes, reversible. Automate with a staged rollout and a fast rollback path. The human's job is not to approve each action but to own the kill switch and watch the leading indicators. A feature flag is a better control here than a signature.
High stakes, irreversible. This is the only quadrant that genuinely requires a human decision before the action. Moving money, deleting data, communicating externally on the company's behalf, anything with legal effect. Everything else is negotiable; this is not.
Make the gate worth a human's time
Having concentrated approvals into the quadrant that needs them, the second half of the job is to make each one substantive. A gate that presents a diff and an approve button is a gate that will be clicked. A gate that presents the change, the requirement it serves, the decisions it is bound by, the policies it passed, the one it waived and why, and the specific question the system wants answered — that is a decision a senior person can actually make.
Our rule of thumb: if the reviewer cannot articulate what they are being asked to judge, the gate is badly designed, not the reviewer.
The number that matters
Track approval rate. A gate approving ninety-nine percent of what reaches it is telling you something: either the upstream controls are good enough that the gate is redundant, or the gate has stopped functioning. Both call for a change, and neither is visible if nobody is looking at the ratio.
The goal was never to keep humans in the loop. It was to keep human judgment in the places where it changes the outcome — and to stop spending it everywhere else.
Comments
Loading…
Leave a comment