
Everyone says their agent has a human in the loop. Ask four questions and most answers fall apart. What makes the agent stop? Who gets the case? Who gets it when that person is away? What happens if nobody answers? A hold that answers all four is a control. A hold that answers two is a notification.
In one sentence: a hold is a trigger, one named approver, a named cover and a time limit, and it fails quietly when any one of them is missing.
Where it comes from
Your delegation of authority already has holds. Invoices over a limit need a second signature. New suppliers need a check before first payment. The agent version borrows the same logic and adds speed.
Security guidance says the same thing in its own words. OWASP's advice on excessive agency: "Utilise human-in-the-loop control to require a human to approve high-impact actions before they are taken"3. It adds that this "may be implemented in a downstream system (outside the scope of the LLM application)"3. The hold does not have to live inside the agent. It is often better when it does not.
The EU AI Act sets the bar for high-risk systems. Deployers must give oversight to people "who have the necessary competence, training and authority, as well as the necessary support"2. Those people must be able "to decide, in any particular situation, not to use the high-risk AI system or to otherwise disregard, override or reverse the output"1.
How it works
Four parts. Each one answers a question the others cannot.
1. The trigger. What makes the agent stop. Write it as a fact about the case, not a feeling about the agent. "Payment over 250.00." "Bank details first seen in the last 30 days." "Claim value over the adjuster's authority." "Agent confidence below the level you set." Facts can be checked before the action runs. "Anything risky" cannot.
2. One named approver. A person, by name, with authority to say yes and no. Not a team. Not a channel. When five people can answer, each assumes another will. Name one. The AI Act's words fit: competence, training, authority, support2. An approver who cannot decline is decoration.
3. A named cover. The approver will be on holiday during close. Name the second person now, and say when the case moves to them. Without cover, the first absence becomes an outage. Or someone shares a login.
4. A time limit, and what silence means. Holds sit. Decide what happens when nobody answers in time. There are three choices: escalate to the cover or a manager, expire (the action does not happen, the case goes back to a human queue), or proceed. For money, only the first two are safe.
Here is one hold, written out. Numbers are illustrative.
| Part | AP example |
|---|---|
| Trigger | Payment over 250.00, or bank details first seen within 30 days |
| Approver | AP lead, by name |
| Cover | Controller, by name, after 4 business hours or when the AP lead is marked away |
| Time limit | 1 business day. Then the payment expires and returns to the manual queue |
| Evidence shown | Invoice, PO, receipt, supplier history, the rule that fired, the proposed payment |
| Recorded | Who decided, when, which option, the reason given |
The evidence row matters as much as the other four. Your approver should see the proposed action and the facts behind it. Not a summary the agent wrote about itself. The rule that fired tells them why they are looking.
What it is good at, and what it is not
Good at. Putting judgment exactly where the rules cannot decide. Most of the queue flows. The hard cases reach a person with the evidence already gathered. The record shows who decided and why. That is what an auditor asks for.
Not good at. Protecting you from a tired approver. Parasuraman and Manzey reviewed the research on automation bias. It "occurs in both naive and expert participants, cannot be prevented by training or instructions, and can affect decision making in individuals as well as in teams"4. The AI Act names the same risk. It wants overseers to stay "aware of the possible tendency of automatically relying or over-relying on the output"1. A hold that sends 200 cases a day to one person produces 200 approvals a day. Size the hold rate to the person.
Easy to get wrong. Default behaviour. Tools pick a default for silence and failure, and it is not always the safe one. Microsoft's multistage approvals, for example, continue to the next stage when an AI stage "fails to give an approve or reject decision"5. Read what your tool does. Then set it.
What to check
- /01
Is every trigger a checkable fact? Could a machine decide, before the action, whether it fired?
- /02
Does each hold name one person? Does it name a cover, and when the case moves?
- /03
What does silence mean? Show me the setting.
- /04
What does the approver see? The proposed action and the evidence, or a summary?
- /05
How many holds does each approver get per day? Who watches that number?
- /06
Is every decision recorded with name, time and reason?
Where it is going
Holds are getting cheaper to build and easier to overuse. Every workflow tool now has an approval step. Our view: the next problem is not missing holds but too many. Teams will start measuring approver load the way they measure queue length. The winners will tune triggers until each hold is worth a person's attention.
Gatehouse fit
In Gatehouse the triggers live in the signed rules, so a hold fires on a fact, before the action runs. The run pauses and the case goes to one named approver, never a shared inbox. The evidence is gathered before they are asked. Their decision and reason are saved with their name in the record. Cover and silence are yours to decide; ask to see them set for your process. The Gatehouse page walks through one simulated held payment.
At a glance
| Category | Controls |
|---|---|
| Also called | Human in the loop, approval step, escalation, maker-checker |
| Borrowed from | Delegation of authority. Payment approval workflows |
| Key standards or docs | AI Act Art. 14 and 26(2). OWASP LLM06:2025 mitigation 6 |
| Typical owner | The process owner sets triggers. The named approver decides. Risk reviews hold rates |
| The one test | Who gets this case when the approver is on holiday, and what happens if nobody answers? |
Sources
- [1]Regulation (EU) 2024/1689 (AI Act), Article 14: Human oversightartificialintelligenceact.eu In text
- [2]Regulation (EU) 2024/1689 (AI Act), Article 26: Obligations of deployers of high-risk AI systemsartificialintelligenceact.eu In text
- [3]LLM06:2025 Excessive Agency, OWASP Top 10 for LLM Applicationsgenai.owasp.org In text
- [4]Parasuraman and Manzey, Complacency and bias in human use of automation, Human Factors, 2010 (PubMed abstract)pubmed.ncbi.nlm.nih.gov In text
- [5]Multistage and AI approvals in agent flows (preview), Microsoft Copilot Studio docslearn.microsoft.com In text
Read next

What is human in the loop AI?
It works when one person you name reviews only what the system is unsure of. You set where “unsure” starts.

What is an agent approval policy?
An approval policy decides which agent actions go ahead, which wait for a person, and which never happen. Most teams have a paragraph. You need a table.

The two-person rule for AI agents: overrides, dual authorisation, and Meta's Rule of Two
Two people to override a block. Where the rule comes from, what it should cover for an agent, and why Meta's 'Agents Rule of Two' is a different rule with a confusing name.