Why HITL matters in agentic commerce
An AI agent that buys entirely on its own is convenient and slightly frightening. An algorithmic
error, a model hallucination or an ambiguous instruction can turn into real financial loss: the
wrong product, the wrong amount, the wrong delivery address.
Human-in-the-loop is the architectural principle that says the agent does the work while the person
keeps control of the critical decisions. It is not a sign that the agent is weak — it is a
deliberate design for trust.
The spectrum of autonomy
Agent systems live on a spectrum between full HITL and full autonomy:
Full HITL Full autonomy
| |
| The agent The agent acts, The agent does |
| prepares, the the human confirms everything |
| human decides the final step inside a mandate |
| every step |
In mature agent products the HITL points are chosen deliberately: only for actions that are
irreversible, expensive or outside normal behaviour.
HITL in shopping flows
| Agent action | HITL needed | Why |
|---|---|---|
| Search and comparison | No | Reversible, no consequences |
| Adding to the basket | No | Reversible — it can be removed |
| Applying a promo code | No, or soft (a notification) | Reversible |
| Placing an order | Yes | Irreversible, financial consequences |
| Reordering | Depends on the amount | Can be automatic inside a mandate |
| Changing the delivery address | Yes | High risk of error |
| Returning a product | Yes | Irreversible once confirmed |
Implementing HITL
Explicit confirmation
The agent finishes preparing the order and waits for the user to press Confirm. This is the
strictest option — easy to understand, but it slows the flow down.
A cancellation window
The agent announces the action it is about to take and performs it after N seconds unless the user
presses Cancel. This lowers friction for standard actions.
Limits and mandates
The user sets the parameters in advance: purchases up to $60, only from the wishlist, only on
discount. Inside those parameters the agent is autonomous; outside them it asks.
Tip: when designing an agent flow, start with maximum HITL and remove confirmation points
gradually as user trust and agent reliability grow. The reverse path — from autonomy back to HITL
after an incident — is far harder.