surehand
All articlesControls

How a hold works: triggers, named approvers, cover and time limits

Reference5 min readSurehand

Everyone says their agent has a human in the loop. Ask four questions and most answers fall apart. What makes the agent stop? Who gets the case? Who gets it when that person is away? What happens if nobody answers? A hold that answers all four is a control. A hold that answers two is a notification.

In one sentence: a hold is a trigger, one named approver, a named cover and a time limit, and it fails quietly when any one of them is missing.

Where it comes from

Your delegation of authority already has holds. Invoices over a limit need a second signature. New suppliers need a check before first payment. The agent version borrows the same logic and adds speed.

Security guidance says the same thing in its own words. OWASP's advice on excessive agency: "Utilise human-in-the-loop control to require a human to approve high-impact actions before they are taken"3. It adds that this "may be implemented in a downstream system (outside the scope of the LLM application)"3. The hold does not have to live inside the agent. It is often better when it does not.

The EU AI Act sets the bar for high-risk systems. Deployers must give oversight to people "who have the necessary competence, training and authority, as well as the necessary support"2. Those people must be able "to decide, in any particular situation, not to use the high-risk AI system or to otherwise disregard, override or reverse the output"1.

How it works

Four parts. Each one answers a question the others cannot.

1. The trigger. What makes the agent stop. Write it as a fact about the case, not a feeling about the agent. "Payment over 250.00." "Bank details first seen in the last 30 days." "Claim value over the adjuster's authority." "Agent confidence below the level you set." Facts can be checked before the action runs. "Anything risky" cannot.

2. One named approver. A person, by name, with authority to say yes and no. Not a team. Not a channel. When five people can answer, each assumes another will. Name one. The AI Act's words fit: competence, training, authority, support2. An approver who cannot decline is decoration.

3. A named cover. The approver will be on holiday during close. Name the second person now, and say when the case moves to them. Without cover, the first absence becomes an outage. Or someone shares a login.

4. A time limit, and what silence means. Holds sit. Decide what happens when nobody answers in time. There are three choices: escalate to the cover or a manager, expire (the action does not happen, the case goes back to a human queue), or proceed. For money, only the first two are safe.

Here is one hold, written out. Numbers are illustrative.

PartAP example
TriggerPayment over 250.00, or bank details first seen within 30 days
ApproverAP lead, by name
CoverController, by name, after 4 business hours or when the AP lead is marked away
Time limit1 business day. Then the payment expires and returns to the manual queue
Evidence shownInvoice, PO, receipt, supplier history, the rule that fired, the proposed payment
RecordedWho decided, when, which option, the reason given

The evidence row matters as much as the other four. Your approver should see the proposed action and the facts behind it. Not a summary the agent wrote about itself. The rule that fired tells them why they are looking.

What it is good at, and what it is not

Good at. Putting judgment exactly where the rules cannot decide. Most of the queue flows. The hard cases reach a person with the evidence already gathered. The record shows who decided and why. That is what an auditor asks for.

Not good at. Protecting you from a tired approver. Parasuraman and Manzey reviewed the research on automation bias. It "occurs in both naive and expert participants, cannot be prevented by training or instructions, and can affect decision making in individuals as well as in teams"4. The AI Act names the same risk. It wants overseers to stay "aware of the possible tendency of automatically relying or over-relying on the output"1. A hold that sends 200 cases a day to one person produces 200 approvals a day. Size the hold rate to the person.

Easy to get wrong. Default behaviour. Tools pick a default for silence and failure, and it is not always the safe one. Microsoft's multistage approvals, for example, continue to the next stage when an AI stage "fails to give an approve or reject decision"5. Read what your tool does. Then set it.

What to check

  1. /01

    Is every trigger a checkable fact? Could a machine decide, before the action, whether it fired?

  2. /02

    Does each hold name one person? Does it name a cover, and when the case moves?

  3. /03

    What does silence mean? Show me the setting.

  4. /04

    What does the approver see? The proposed action and the evidence, or a summary?

  5. /05

    How many holds does each approver get per day? Who watches that number?

  6. /06

    Is every decision recorded with name, time and reason?

Where it is going

Holds are getting cheaper to build and easier to overuse. Every workflow tool now has an approval step. Our view: the next problem is not missing holds but too many. Teams will start measuring approver load the way they measure queue length. The winners will tune triggers until each hold is worth a person's attention.

Gatehouse fit

In Gatehouse the triggers live in the signed rules, so a hold fires on a fact, before the action runs. The run pauses and the case goes to one named approver, never a shared inbox. The evidence is gathered before they are asked. Their decision and reason are saved with their name in the record. Cover and silence are yours to decide; ask to see them set for your process. The Gatehouse page walks through one simulated held payment.

At a glance

CategoryControls
Also calledHuman in the loop, approval step, escalation, maker-checker
Borrowed fromDelegation of authority. Payment approval workflows
Key standards or docsAI Act Art. 14 and 26(2). OWASP LLM06:2025 mitigation 6
Typical ownerThe process owner sets triggers. The named approver decides. Risk reviews hold rates
The one testWho gets this case when the approver is on holiday, and what happens if nobody answers?

Sources

  1. [1]Regulation (EU) 2024/1689 (AI Act), Article 14: Human oversightartificialintelligenceact.eu In text
  2. [2]Regulation (EU) 2024/1689 (AI Act), Article 26: Obligations of deployers of high-risk AI systemsartificialintelligenceact.eu In text
  3. [3]LLM06:2025 Excessive Agency, OWASP Top 10 for LLM Applicationsgenai.owasp.org In text
  4. [4]Parasuraman and Manzey, Complacency and bias in human use of automation, Human Factors, 2010 (PubMed abstract)pubmed.ncbi.nlm.nih.gov In text
  5. [5]Multistage and AI approvals in agent flows (preview), Microsoft Copilot Studio docslearn.microsoft.com In text

Read next

[ your next step ]

Bring us the queue nobody wants.

One process, studied in writing. You keep the document, whatever it says.

support@surehand.io