Human in the loop AI, when you are the only human
Updated
Human in the loop means a person reviews or approves what an automated system does at the points where it matters. Most writing about human in the loop AI agents assumes a company: reviewers, approval queues, escalation paths. When you work alone, you are the only human in the loop. That is simpler, and it still needs a little structure.
What human in the loop means
An AI agent can take many steps on its own. Human in the loop, often written HITL, is the rule that some of those steps wait for a person. The person might approve a plan, answer a question, check a result, or undo a mistake.
There is a spectrum. At one end, the agent asks before every action, and you might as well do the work yourself. At the other end, it never asks, and you find out what happened when something breaks. The useful middle is to pick the few moments that need you, and let the agent run freely between them.
Why it matters more when you are alone
In a team, a second person often catches what the first missed. Alone, there is no second person. Your attention is also the scarcest thing you have. If the agent asks too often, you stop reading. If it never asks, you stop trusting. Both end the same way.
So the goal is not maximum oversight. It is oversight in the right places, delivered somewhere you will actually see it. In practice that somewhere is the same place you already keep your projects, which is why this is really a question of personal project management and not of AI settings.
Decisions that stay with you
Write these down once, where the agent will see them before it starts. A short note at the top of the project works. Anything on the list means stop and ask.
- Scope. Adding work nobody asked for, or dropping something that was agreed.
- Anything irreversible. Deleting things, cancelling bookings, overwriting the only copy of something.
- Money. Paid services, prices, anything that bills someone.
- Other people. Sending email, posting publicly, promising a customer anything.
- Access. Passwords, accounts, anything that gives someone more reach than before.
- Going live. Deciding that a change is published, sent or released.
Everything else the agent can decide, and tell you about afterwards: how to word a draft, which sources to check first, what order to do things in.
Blocked, with a concrete ask
When the agent reaches one of those decisions, it needs a way to stop that you will notice. A message buried in a long chat is easy to miss. A ticket status is not.
Give the agent a blocked status and one rule: blocked always comes with a note that says exactly what it needs. Not "I have a question", but a question you can answer in one line. For example:
- "The venue on the 12th is booked. Option A: move the workshop to the 19th. Option B: ask the second venue for a quote. Which one?"
- "The supplier raised the price of the part. Order at the new price, or wait for your call?"
You open the project, see the blocked ticket, reply in the thread, and move it back to in progress. The agent picks it up from there. Nothing depends on both of you being available at the same time.
Review before it goes live
The most useful checkpoint is between finished and live. Split them into two statuses. Done means the agent finished the work and the thread says what it did. Deployed means the change is confirmed live, not just prepared.
Your review goes in the gap. Read what it wrote, look at the result, then let it go out. If you are happy to let the agent publish small things itself, say which things, and still ask it to confirm the change is live before it marks the ticket deployed. The guide to managing AI agents when you work alone covers how to keep that rhythm without checking in every hour.
Scoped access you can revoke
Human in the loop is also about what the agent can reach when you are not looking. Keep that small.
- One agent, one project. The agent helping with your website should not see the tickets for your tax paperwork.
- Only what it needs. Reading, filing tickets, commenting and changing status cover most work. Deciding the project's labels and statuses can stay with you.
- Revocable at once. If something looks wrong, you revoke its access and the agent is out. What it already wrote stays for you to read.
- A name on every change. Each comment and status change should say who made it, so you can tell your own notes from the agent's.
A trail you can read later
The last part of the loop happens weeks later, when you wonder why something is the way it is. If the reasoning only lived in a chat, it is gone.
Ask the agent to report in the ticket: what it tried, what it changed, what it was unsure about. Every status change, with its note, lands in the same thread. The result is a record you can skim on your phone, and one the agent can read again the next time it picks up related work.
A small setup to copy
- A project per piece of work, and the agent connected to only the project it works on.
- A short list of stop-and-ask decisions where the agent will see it.
- Blocked always carries a question you can answer in one line.
- Done and deployed are separate, and you review in between.
- Every report goes in the ticket's thread.
That is what human in the loop AI agents look like for a team of one. You stay in charge of what matters, and the agent gets long stretches of uninterrupted work. For the wider setup, see using an AI agent for project management.
Very Simple Projects is a simple personal project management app built around exactly this: projects, numbered tickets, six statuses plus your own, and a thread on every ticket. Blocked needs a note, an agent gets its own revocable token for one project, and it can never delete a comment. It costs $0.99 a month, and the first month is free.