Human in the loop

The AI does the work. You keep the decisions.

Human-in-the-loop means a person can stop, steer or approve what the AI is doing, at the moment it matters rather than in a report afterwards. It is not one setting — it is a set of controls at different distances, from reading every draft to being asked once before money moves.

Calling Northwood Insurance 4m 12s · caller still on the line

The agent is asking you

They are asking for the patient’s policy group number. I do not have it — what should I give them?

Group 4471-B, and the member ID ends 8823

Sends straight into the live conversation

The agent stops rather than guessing, and the call stays open while it waits. What you type goes into the live conversation, not into a note somebody reads afterwards.

Or just ask for it

The dial is wherever you are.

Turn autonomy up or down, and answer the questions it stops to ask — in the thread you were already in.

from:octo needs you
OctoConfirm: refund $1,240 — YES 5583 — Expires in 24 hours, one use2:04pm
OctoNeeds you: caller wants a discount — She is on the line now11:31am
Octosupport@ moved to draft mode — Nothing sends without a personMon

InboxConfirm: refund $1,240 — YES 5583

OOcto2:04 PM

Kepler asked for a refund of $1,240 and the thread supports it. Money stops here by design — reply YES 5583. One use, expires in 24 hours.

Dme2:11 PM

YES 5583. And keep stopping on anything over $500.

Octoonline
what’s it allowed to do without asking?9:05 AM ✓✓
Safe things — reading, drafting, tagging. Money, mass messages, destructive actions and live-deployment changes all stop for a code.9:05 AM
a caller is asking for a discount, what do I do11:31 AM ✓✓
That’s the agent asking you, mid-call. She’s still on the line — tell me the answer and I’ll put it into the conversation.11:31 AM
offer 10%, no more11:32 AM ✓✓
Injected into the live call. It didn’t hang up and start again.11:32 AM
Message
#omniocto4 members
MRMarcus4:20 PM

@Octo stop sending on support@, drafts only until I say otherwise

OOctoAPP4:20 PM

On it 🔧(runningconfigure_email_channel…)

Draft-for-approval. Any single thread can still override it in either direction. (edited)

🔒 3

2 replies · last reply 9m ago

DWDana4:38 PM

and route the YES codes to this channel too

Message #omniocto

Email octo@agent.omniocto.com · WhatsApp 1-MAN-ASK-OCTO · Slack #omniocto

Why this is a page of its own

Autonomy is a dial, and the dial is the product.

The objection to putting AI in front of customers is never "can it write" — it is "what will it send". So every capability below is a place where a person can be in the path, and most of them default to the cautious end.

It writes, you press send
Draft mode composes the reply and leaves it in your own Gmail or Outlook Drafts folder. Nothing reaches a customer until a person approves it, and approving the same draft twice cannot send it twice.
Per-thread, not just per-mailbox
Autonomy is a default you set per channel and can override on any single thread. Most people leave a mailbox in draft mode and let a handful of routine threads run alone — or the reverse, with one difficult customer pinned to human-only.
It stops and asks you, mid-call
When the agent hits something only a person can answer, the question appears on your dashboard while the caller is still on the line. You type the answer and it goes into the live conversation rather than the call being abandoned.
You can steer a call without restarting it
Send an instruction into a call in progress, listen in, mute, or take it over entirely. Watching it take a wrong turn does not mean hanging up and beginning again.
It knows when to stop trying
Escalation rules decide when a conversation should go to a person instead — a repeated failure to help, someone asking for a human, a subject you flagged. The handoff happens on the call, not in an email an hour later.
A code before anything is spent
Money, mass messages and destructive actions stop with a plain-language description of what is about to happen and a short code to reply with. It is good for one use, expires after a day, and the recipient list is frozen at the moment the question is asked — so what you approved is what goes out.
Every tool carries a risk class
Tools are classified safe, spends money, mass message, destructive, or changes a live deployment, and the classification is enforced in the build so a new tool cannot arrive unclassified. Only the harmless class runs without asking.
Workflows can wait for a person
A human-approval step pauses a workflow until someone decides. That is what makes it safe to automate something consequential rather than only the trivial parts.
See what it would do first
A dry run reports what a workflow would do and what it would cost before it does anything, which is the difference between confidence and hope on an automation that messages customers.
A ceiling it cannot talk its way past
A monthly model budget and a daily voice-minute cap per workspace, with alerts at 50%, 80% and 100%. Reaching a cap stops the work rather than reporting it after the money is gone.
The person on the other end is told
Spoken AI disclosure is on by default on every call, with wording you control or a recording of a real voice that plays verbatim. Each call keeps an audit row of what the person was told.
It tells you which ones need you
Every conversation is graded for whether a human specifically needs to act, separately from how urgent it is. Being in the loop is only useful if you know which loop to be in.

Where you see it

The jobs these controls sit inside.

Start

Start it at the cautious end.