Agent governance Human override
Agent Privileging · Component 4

Human override

"Human in the loop" is a slogan until three questions have procedural answers: who may halt this agent, how long a halt takes to bite, and where the halt itself is recorded. The override protocol answers all three in writing.

Who: broad to stop, narrow to restart

The defensible asymmetry mirrors clinical practice: anyone in the affected workflow may trigger a halt — a scheduler who sees the agent double-booking does not need permission to stop it — while restarting requires the named accountable owner. Organizations that restrict halting to administrators have optimized for the wrong failure: an unnecessary pause costs minutes; an unstoppable agent costs the incident.

How fast: measure the halt path

An override that takes a ticket queue is not an override. The halt path — from "stop it" to the agent provably stopped — should be measured in minutes, tested before go-live, and re-tested when integrations change, the way fire doors get inspected. If the vendor cannot demonstrate a same-hour halt, that is a finding about the vendor, recorded before contract signature.

Recorded, both directions

Every halt and every restart goes on the permanent record: who, when, why, and what was reviewed before resuming. Halts that leave no trace teach the organization nothing and protect nobody; a pattern of halts on the record is exactly the signal that should trigger a privileging review. The restart rationale requirement is deliberate friction — an agent that was worth stopping is worth a written sentence before it acts again.

Part of the complete healthcare AI governance guide.