← All posts
§ Blog

Approval fatigue

Approval fatigue: the human gate fails when it is a click. Bounded escalate, named reviewer, revoke. Presence of an overseer is not oversight.


Approval fatigue

The operator is not reading. They are clicking.

Twelve Trust dialogs. A path in each. A verb. Allow. The coffee has not cooled. The queue has.

By the third dialog the person is already a signature. The finger is doing the oversight. The job continues because someone initialled a bound they did not look at.

I already wrote that HiTL for a callable tool is identity as the gate, not a person in the thread. I already wrote that the score is the environment, not the writer grading itself. This note is what happens to the person who still has to initial the bound.

When they skim-approve, they cannot take over when the bound fails. The click trained the finger. It did not train the overseer.

The expert lock still holds. A skill becomes a platform object. A headless agent is a job, a machine, and a schedule. HiTL is an SLA. Approval fatigue is how that SLA dies in the chair.

A click is not HiTL

A Trust dialog is a permission pop-up. It is not a review. It is not a named person. It is not a bound you can revoke after the finger has already said yes.

Vendors will call that human-in-the-loop. The loop is real. The human is a click.

The disease is not that agents ask for permission. It is that they ask so often, and at such a small grain, that the only cheap answer is Allow. The expensive answer - read the path, picture the miss, refuse - does not fit the queue.

The dialog is the same size whether the action is nothing or the one that cannot be undone. The muscle learns the size, not the stake.

So “we have HiTL” can mean two artefacts. A trained overseer who can still do the work, and will put a name on a miss. Or a signature harvested from whoever happened to be in the thread.

What the paper actually said

Mitchell (Hugging Face), Ghosh (Hugging Face), and Passi (Data & Society) put this in an August 2026 position paper (arXiv 2608.23642). The title is the claim: AI agents push humans out of the loop.

That paper is theirs. I did not run their study. I am not going to dress their citations as an overnight I did not run.

They argue that current agent design does not merely forget oversight. It degrades it. Approval fatigue. Overreliance. Loss of situational awareness. Skill atrophy. The presence of an overseer is not reliable oversight. That sentence is theirs. It is also the room with the Trust dialogs.

They reach for Bainbridge (1983) on the irony of automation: the more capable the system, the less prepared the human when it fails. The cases where a person is supposed to matter - rare, ugly, needing judgement - are the cases the click has already taken the skill from.

They cite Kosmyna et al. on brain connectivity under LLM use. That measurement is theirs, in their references. I did not run an EEG. I am not going to invent numbers and put my name on them.

What they want built, they split in two. Developers: design-level affordances. Deployers: organisational protocols. Neither prong alone.

On the design side they name bounded autonomy - what the agent may do without a person - batch review of a logical unit, and action gating before a consequential path. On the organisation side they name role separation, rotations, and domain-skill maintenance without the model. Trainings. Breaks. A programme of unaided work, or there is nobody left who can see a miss.

I am not going to restate their inventory as a product. I am going to cut it to the gate I can actually run.

Design the human gate against atrophy

Skim-approve Trust dialog versus designed human gate

The operational cut is narrower than their table. A bound you can name, a person you can name, a revoke you can time.

Bounded escalate. Write what may run without a person. Everything else stops and waits. Read may run. Write, send, pay, delete wait. An empty list trains skim-approve. A list that says “whatever the agent wants” is a slogan.

Named reviewer. Not whoever is in the thread. A name, on the artefact, before the run. If the name is “the operator on shift,” you have a queue again.

Revoke. After yes, can you still kill the job, pull the grant, stop the next step. A Trust dialog that cannot be undone is not a gate. It is a receipt.

Batch at a logical unit. A permission pop-up per tool is how the finger learns to be fast. Their batch review is a diff of related actions. That is the grain I will steal. Not twelve Allows. One unit of work, read once, initialled once - or refused.

Do not call a Trust dialog a trained overseer unless someone owns the miss. Ownership is not a click. Ownership is who is still able to do the work when the model is wrong.

DimensionSkim-approve Trust dialogDesigned human gate
What you signA permission pop-up per toolA logical unit, batched
Who reviewsWhoever is in the threadA named reviewer
What may run unaidedNothing useful, or everything once Allow is a habitBounded escalate: named actions that may run without a person
What you can undoHope the job finishesRevoke
How the overseer stays ableBy clickingUnaided practice of the same work
What you actually haveA signatureHiTL

The SLA

If you cannot name who reviews, how often they still do the work unaided, and what they can revoke, you do not have HiTL. You have a signature.

Those three questions sit on the same card as the earlier gates. Whose identity is on the call. What scores a revision. What may run when nobody is in the room. This card is about the person who still has to say no.

A name. A cadence of unaided work. A kill you can still pull. If any of those is missing, the dialog was theatre.

I will not publish a night I did not run. The Thursday folder is still a sketch. This SLA does not wait for that folder. It is the test I will put on any gate that asks a person to initial an agent.

What this is not

This is not a remake of Identity is the gate. That note was whose token is on the call. This one is the person who still has to initial the bound.

It is not a remake of Owner, verifier, gate. That note was the artefact: owner, verifier, load gate. The score is still the environment. This note is the overseer atrophying in the chair.

It is not a recap of a tweet. It is not my EEG. It is not a claim that I ran Mitchell, Ghosh, and Passi’s study. Their paper is the citation. The Trust dialog is the room.

It is not a live council of named personas, and it is not a promise that the Thursday folder will be ready next week. A sketch is a sketch. Another click in the thread is still a click. The gate is the bound, the name, and the revoke.

Steal this

You do not need my desk. You need five names on a card before the next Trust dialog.

  1. Write the bound. What may run without a person. Everything else escalates. If the list is “all tools,” you will train skim-approve.
  2. Name the reviewer before the run. Not the thread. Not whoever has the laptop open. A person who will own the miss.
  3. Time the revoke. If you cannot kill the job or pull the grant, you did not gate it. You signed it.
  4. Batch at a logical unit. A permission pop-up per tool is a warmup for the finger. One unit of work, read once.
  5. Keep unaided practice. If nobody still does the work without the model, you do not have an overseer. You have a witness.

The product question is no longer whether a human clicked Allow. It is whether that human could still have said no, and whether anyone can name them after the click.


Field note from the build-in-public log. NDA-safe, no client names, rounded figures only. If this matches what you are seeing, get in touch.

§

BELOW THE LINE

PODČÁRNÍK · SIDEWAYS GLANCE, NOT A SUMMARY

On the colleague who practised Approve until his finger had a groove

He stays late. The real work waits in the other room. In this one the dialogs are empty on purpose. He clicks Approve. He clicks it again. A groove is forming in the finger.

They used to stretch before the shift. Arms up, arms down, so the body would not seize on the line. He has that ritual, except the stretch is a button. Empty dialogs, like a typewriter with the ribbon taken out. The paper stays blank. The hand does not.

Coffee after. The cup is the receipt. He smiles in the corridor. Form, he says. The finger is loose. Nobody asks what he practised. Warmup looks like diligence if you only see the smile.

A real dialog finally appears. Same size. Same verb. Same corner of the screen. He clicks the same way. The groove knew the path. The work in the other room is still the work in the other room.

Nobody asked him to practise. That is the part that is not funny. He invented the empty click so he would not be slow when it counted. He was not slow. He was already finished before he had started.

The finger was ready. The person was not.

ČESKY. ORIGINAL PODČÁRNÍK

O kolegovi, který cvičil Schválit, až mu v prstu zůstala rýha

Zůstává déle. Skutečná práce čeká ve vedlejší místnosti. Tady jsou dialogy prázdné. Záměrně. Klikne Schválit. Klikne znovu. V prstu se kreslí rýha.

Kdysi se u pásu dělala rozcvička. Ruce nahoru, ruce dolů, ať tělo na lince neztuhne. Má tutéž rozcvičku, akorát je z tlačítka. Prázdné dialogy, jako psací stroj s vytaženou páskou. Papír zůstane bílý. Ruka ne.

Kafe potom. Šálek je stvrzenka. Na chodbě se usměje. Formu mám, řekne. Prst je volný. Cvik je malý bordel. Z úsměvu to vypadá jako pečlivost.

Pak konečně přijde opravdový dialog. Stejné okno. Stejné sloveso. Stejný roh obrazovky. Klikne stejně. Rýha znala cestu. Práce ve vedlejší místnosti pořád čeká ve vedlejší místnosti.

Nikdo ho o cvičení neprosil. To je ta část, která není vtipná. Vymyslel si prázdný klik, aby nebyl pomalý, až to bude platit. Pomalý nebyl. Byl hotový dřív, než začal.

Prst byl ready. Člověk ne.