Human-in-the-Role: a technical note on binding authority
How a standing grant is expressed, bounded, enforced, revoked and evidenced — the mechanics behind the phrase.
By Odero Otieno — Founder, CEO & CTO, Dipp AI Technologies, Inc.
A specification-level note on Human-in-the-Role: the structure of a standing grant, the bounds it carries, the evaluation performed at execution time, the escalation path when no grant applies, and the record the pattern leaves behind.
Human-in-the-loop is a workflow pattern. Human-in-the-Role is an authority model. The difference is not rhetorical: one places a person in the path of each item and depends on their attention, the other places a bounded, revocable grant in the path of a class of actions and depends on its enforcement. This note describes the second in enough detail to be argued with.
FIG. A01-02
The population an accountable owner would have to govern
Drag the inputs
Published 2026 estimates put the enterprise ratio between 45:1 and 140:1 depending on company size. Independent research finds roughly 28% of agent actions can be traced back to a human sponsor across every environment they touched.
400,000
Non-human identities in the estate
112,000
Of those, traceable to a human sponsor
288,000 unaccounted
Dipp AI · Orcher
Fig. 1 — Agent identities per accountable human role. The ratio that makes per-item review structurally unavailable.
Anatomy of a standing grant
Field
Meaning
Example bound
Role
The accountable human role, not an individual account
Claims Adjudication Lead
Directive class
The class of action permitted
Adjudicate claim, value ≤ threshold
Value bound
Maximum consequence permitted per action and per period
$25,000 per action
Data class
Which classes the action may touch
PHI permitted, in-region models only
Jurisdiction
Legal regimes eligible to process
US only
Temporal bound
Validity window and review date
90 days, reviewed quarterly
Escalation target
Where refusals go
Director of Claims Operations
Table 1 — A grant is a structured object, not a permission flag.
Evaluation at execution time
The agent presents a directive with its class, value, data class and target system.
The Role Identity Fabric resolves grants in force for that directive class at that instant.
Each bound is tested. A single failing bound is sufficient to refuse.
On success, the role is attached to the action and carried through routing, boundary and ledger records.
On failure, the action stops and escalates to the grant's escalation target with the failing bound named.
FIG. A02-01
Review after the fact, versus authority before it
Step through the cycle
Lane A — Human-in-the-Loop
01 Agent plans
The agent composes an action from context nobody scoped in advance.
02 Agent acts
Execution happens against the production system of record.
03 Reviewer sees a result
A plausible-looking summary arrives in a queue, on a clock.
04 Approve or miss
Under volume, approval becomes the default. Nothing proves scope.
05 Damage is historical
The record starts after the fact, if it exists at all.
Lane B — Human-in-the-Role
01 Directive issued
A named professional states intent under their own authority.
02 Role bound
Role Identity Fabric binds the directive to that authority, cryptographically.
03 Gates evaluated
Authority, action and data-boundary gates run in sequence, halting by default.
04 Action commits
Only a directive that cleared every gate reaches the system of record.
05 Evidence written
The Immutable Audit Ledger records the cycle — including any halt.
Step 1 / 5
Dipp AI · Orcher
Fig. 2 — The same action under review-after-the-fact and under a bounded standing grant.
Why revocation matters more than approval
Approval systems accumulate permissions and rarely shed them, because nothing forces re-examination. A grant carries a temporal bound and a review date, so authority expires by default and must be renewed deliberately. Revocation is immediate and takes effect on the next evaluation, which means withdrawing authority does not require finding and disabling every agent that relied on it.
Role
the unit of accountability
Not the individual, and not the agent
Expiry by default
authority lifecycle
Refuse and escalate
behaviour outside the bounds
Common objections
The first objection is that this is simply role-based access control. It is not: RBAC governs what a principal may reach, while a grant governs what consequence an autonomous action may cause, bounded by value, data class and time, and it is evaluated per directive with the outcome written to evidence. The second objection is that it slows delivery. In practice it moves the conversation earlier — bounds are agreed once, in daylight, rather than negotiated repeatedly under incident pressure.
“An approval records that someone clicked. A grant records that someone is answerable. Only one of those survives an inquiry.”
Sources
Sources for every figure in this article.
Where a number comes from Dipp AI's own analysis or an observed deployment, it is labelled as such and is not presented as an independently audited third-party finding.
Dipp AI Technologies, The Enterprise Superintelligence Report, Vol. I (August 2026)
Case studies
Organisations that ran this argument in production.
Modelled reference scenarios with the measurement window, the components enforced and the numbers attached. Each one downloads as a PDF.
Writes the Dipp AI record on enforced governance for agentic systems — authority, enterprise data boundary, cost and compute. Every figure in this piece carries a source, and corrections are published on the record rather than made quietly.