GovernanceSeptember 28, 2026·George Schildge·5 min read

Human-in-the-loop vs. human-on-the-loop: setting the autonomy ceiling for each revenue action

Six revenue action classes listed from internal research to pricing outreach, each marked with where an error would land and whether it can be undone.

Human-in-the-loop means an action is held until a named person approves it. Human-on-the-loop means the action runs under a standing policy while a person supervises and can intervene or revoke. RevOps shouldn’t choose one model for everything. The right approach sets an autonomy level for each action class, based on where an error would land and how much trust the workflow has earned.

Two terms that are not interchangeable

The oversight debate often collapses into “is there a human involved or not?” That framing hides the decision RevOps actually has to make. There are two distinct oversight models:

Human-in-the-loop (HITL). The action is drafted and held. It does not execute until a named person on your team approves it.

Human-on-the-loop (HOTL). The action executes under a standing policy your team sets. A named person supervises and keeps intervention, override, and revocation authority.

Your team chooses the mode for each action class, based on its risk tolerance, and can change it at any time.

Every action, in either mode, is recorded to the audit ledger with its rationale, before-and-after state, and the approver or policy behind it.

Every action class starts in human-in-the-loop until your team changes it.

In the first, approval is a precondition. In the second, oversight is continuous instead of transactional: the supervisor reviews through the record of actions.

Neither is safer in the abstract. Holding high-volume, low-risk actions for approval creates a queue nobody reads carefully, which is oversight theater. Running customer-facing actions under policy in an untested workflow puts your brand ahead of your data quality.

What the research firms say

The research firms are converging on a view that oversight has to scale with agent use. Gartner predicts that 70% of AI apps will use multi-agent systems by 2028. Its analysts argue that when agents interact with each other at machine speed, human oversight alone is no longer enough, and automated controls are needed alongside people (Gartner, June 11, 2025).

McKinsey’s 2025 State of AI survey reports that AI high performers are more likely than others to have defined processes for deciding how and when model outputs need human validation. The winning pattern is not “always review” or “never review.” It is a deliberate decision about which outputs get validated.

Forrester puts a price on the alternative. It predicts that ungoverned use of generative AI will cost B2B companies more than $10 billion in enterprise value (Forrester, October 28, 2025). Revenue actions need revenue-specific policy.

A practical framework: set the ceiling per action class

Classify each action by where an error would land and how reversible it is:

Six revenue action classes: where an error lands, whether it is reversible, and the governance mode each can reasonably settle in.
Action classError lands onReversible?Where it can reasonably settle
Account research and scoringInternal priority listYesStanding policy
Internal CRM field updateInternal recordYes, with a before-and-after recordStanding policy
Internal task or alert to a repInternal personYesStanding policy
Outbound to a new prospectProspect, your brandNoHeld for approval
Trial activation messageActive userPartlyHeld until the workflow has earned trust, then policy
Expansion or pricing outreachExisting customerNoHeld for approval

Then move actions up the ceiling only on evidence. When a held action class shows a consistently high approval rate with few edits over a meaningful sample, that is the signal to consider standing policy for it. The record of approvals is the evidence.

George Schildge’s view

How PrescientIQ™ implements it

Action items for RevOps this quarter

  1. List every action class your AI tools can take today, and place each in the table above.
  2. Name an owner for each class, meaning the person accountable for its policy.
  3. For every held class, start tracking the approval rate and edit rate. That is your evidence base.
  4. Set a quarterly review to raise or lower each ceiling based on that evidence, and record the decision.

For the accountability argument behind this framework, see who is accountable when AI acts.

Check the math before you spend anything

The free AAR Benchmark builds a P&L projection on your own pipeline data in a read-only working session. Every figure in it is labeled as modeled.

Get your free AAR Benchmark →

Frequently asked questions

What is human-in-the-loop AI?
Human-in-the-loop (HITL): The action is drafted and held. It does not execute until a named person on your team approves it. It suits high-risk, irreversible actions like outreach to new prospects, but it can become a rubber-stamp queue if it is applied to every low-risk action.
What is human-on-the-loop AI?
Human-on-the-loop (HOTL): The action executes under a standing policy your team sets. A named person supervises and keeps intervention, override, and revocation authority. It suits lower-risk, reversible actions where approving each transaction adds delay without adding real oversight. The record of actions is what the supervisor reviews.
Which revenue actions should be held for approval?
Start by holding actions whose errors would reach prospects or customers and cannot be undone, such as outbound to new prospects and expansion or pricing outreach. Internal research, scoring, and CRM updates recorded before and after can typically move to standing policy with supervision.
When should an action class move to standing policy?
Move it on evidence, not optimism. When a held action class shows a consistently high approval rate and few edits across a meaningful sample, that record supports running it under policy. Review ceilings quarterly and document every decision so the rationale is auditable later.
Why isn’t human review alone enough for AI agents?
Gartner’s analysts argue that as multi-agent systems interact at machine speed, human oversight alone is no longer enough. People can’t review every action at that pace. Effective governance combines defined permissions, per-action policy, and a complete record of actions, with people focused on the decisions that carry the most risk.
How does PrescientIQ handle oversight?
Your team chooses the mode for each action class, based on its risk tolerance, and can change it at any time. Every action class starts in human-in-the-loop until your team changes it. Every action, in either mode, is recorded to the audit ledger with its rationale, before-and-after state, and the approver or policy behind it.

Sources

  1. Gartner, “Gartner Predicts that Guardian Agents will Capture 10-15% of the Agentic AI Market by 2030,” June 11, 2025. Link
  2. McKinsey & Company, “The state of AI in 2025: Agents, innovation, and transformation,” survey fielded June to July 2025. Link
  3. Forrester, “2026 B2B Marketing, Sales, And Product Predictions,” October 28, 2025. Link

Research findings are paraphrased and carry their original publication dates. Predictions are the research firms’, not ours. Recommendations and checklists are the author’s and are offered as a starting point, not as benchmarks.

Where PrescientIQ runs

PrescientIQ is hosted and operated by MatrixLabX on Google Cloud. SOC 2, ISO 27001, and PCI DSS attestations are held by Google Cloud, which operates the underlying infrastructure. They are not MatrixLabX certifications. MatrixLabX application-layer SOC 2 is in progress.