The thesis
Human-in-the-Role
Frontier AI can reason across hours of unattended work. Human-in-the-Role is how Dipp AI makes that autonomy answerable: every action bound to a named professional's authority at the start, enforced at every gate, and provable afterwards.
Human-in-the-Loop vs Human-in-the-Role
Fig. HITR-03
Human-in-the-Loop
L1
Agent proposes
Plausible action, generated at speed.
L2
Person approves
Thirty seconds, low context, high volume.
L3
Action commits
Accountability ends at a click record.
Approval fatigue turns the control into a rubber stamp.
Human-in-the-Role
R1
Role bound at issue
Directive carries the professional's credential.
R2
Enforced at every gate
Scope checked against entitlements, not intent.
R3
Provable afterwards
Who authorized it, on what basis, at what time.

Human-in-the-Loop versus Human-in-the-Role
Fig. HITR-11
Path A · Human-in-the-Loop
Oversight requested at review. Control is a click.
L1
Agent proposes
A plausible action is generated with no scope boundary attached.
L2
Queue
The proposal joins thousands of daily alerts competing for attention.
L3
30-second review
A tired reviewer accepts under time pressure; automation bias sets in.
L4
Timeout → auto-proceed
Unattended items proceed anyway. The click was the only control.
L5
Action commits
No delegated authority, no verifiable record of why it was allowed.
Outcome — 28% of enterprises can trace an agent action end to end.
Path B · Human-in-the-Role
Authority enforced at execution. Control is structural.
R1
Directive from a role
Intent is issued inside a scoped role with declared entitlements.
R2
Authority bound
The role's cryptographic authority is attached before any model runs.
R3
Pre-commit verification
Policy, records and limits are checked as an executable gate, not a memo.
R4
Halt or commit
Out-of-authority work cannot execute — there is nothing to rubber-stamp.
R5
Hashed evidence
The full path is written to an immutable ledger and retained by the firm.
Outcome — every committed action carries provable scope, identity and evidence.
Why the loop fails
Four documented failure modes.
Each one is measured in the literature, not asserted. Together they explain why oversight theater persists in organizations that genuinely intended control.
Approval fatigue
Reviewers facing hundreds of plausible actions approve nearly all of them. Volume defeats attention long before intent does.
Automation bias
When advice is wrong, human accuracy collapses to 45.5% from 82% unaided. The reviewer is not a control; they are a second victim of the error.
Timeout defaults
A thirty-second approval window that auto-proceeds is not oversight. It is a delay before the same outcome.
Reviewer without authority
The person clicking approve often lacks the delegated authority the action requires. The signature is meaningless the moment it is challenged.
Figure · Orcher™
How Human-in-the-Loop fails in production
FIG. P06-01
F1
Approval fatigue
2,992 security alerts a day, 37% ever investigated. Review capacity is finite; agent volume is not.
F2
Gateway timeouts
30-second approval windows auto-proceed when unattended. The default is execution, not halt.
F3
Requisite variety
Ashby's law: a reviewer cannot regulate a system with more states than the reviewer can represent.
F4
Invisible identities
92% have no visibility into non-human identities; 86% enforce no policy against them.
Evidence
The measured gap
45.5%
human accuracy when AI advice is wrong
82% unaided — Vol. I, p.6
2,992
daily alerts; 37% investigated
Vol. I, p.7
30s
typical approval timeout before auto-proceed
Vol. I, p.7
144:1
non-human to human identity ratio
Vol. I, p.11
HITL versus HITR across authority, timing and evidence
Fig. HITR-11B
| Dimension | Human-in-the-Loop | Human-in-the-Role |
|---|---|---|
| Where control sits | In a review queue, after the plan exists | In the execution path, before commit |
| What is enforced | A person's attention | Scope, identity, policy and spend |
| Failure under volume | Degrades — alerts outrun reviewers | Constant — gates do not tire |
| Timeouts | Auto-proceed is common | Halt is the default |
| Evidence produced | An approval click | Hashed, replayable execution record |
| Regulatory posture | Oversight asserted | Oversight demonstrable on demand |
Liability
Someone is already accountable. Software should reflect that.
Regulators, courts, and professional bodies do not recognize autonomous intent. The duty sits with a licensed, delegated, or appointed human — with or without your architecture's cooperation.
Figure · Orcher™
Liability — the autonomy defence is closing
FIG. P12-01
“The machine decided” is not a defence. Liability lands on the organization that deployed the system, and increasingly the burden of proof runs the other way.
The Enterprise Superintelligence Report, Vol. I, p.12
US
California statute, 1 Jan 2026
Forecloses the AI-autonomy defence for deployed systems.
EU
Product Liability Directive
Introduces a presumption of causality the deployer must rebut.
CA
Moffatt v. Air Canada
An organization is bound by what its automated agent told a customer.
REF
Aviation parallel
Crew Resource Management after Tenerife cut crew-error accidents by roughly half — by changing authority structure, not attention.
Output B · Dipp Intelligence
Every verified cycle leaves an asset behind.
OUT.B of the Verified Execution Cycle is Dipp Intelligence — the verified execution path, retained by the enterprise rather than absorbed by a model provider.
Path
The exact sequence that produced a verified outcome.
Role
The authority under which the action was permitted.
Cost
The model tier that actually proved sufficient.
Proof
The hashed evidence a regulator will accept.
From models that will not to systems that cannot.
Human-in-the-Role is implemented, not aspired to: the Role Identity Fabric binds it and the Logic Scrubber enforces it.
