Dipp AI Research · August 24, 2026

Human-in-the-Role: a technical note on binding authority

How a standing grant is expressed, bounded, enforced, revoked and evidenced — the mechanics behind the phrase.

By Odero OtienoFounder, CEO & CTO, Dipp AI Technologies, Inc.

A specification-level note on Human-in-the-Role: the structure of a standing grant, the bounds it carries, the evaluation performed at execution time, the escalation path when no grant applies, and the record the pattern leaves behind.

Human-in-the-loop is a workflow pattern. Human-in-the-Role is an authority model. The difference is not rhetorical: one places a person in the path of each item and depends on their attention, the other places a bounded, revocable grant in the path of a class of actions and depends on its enforcement. This note describes the second in enough detail to be argued with.

FIG. A01-02

The population an accountable owner would have to govern

Drag the inputs

Published 2026 estimates put the enterprise ratio between 45:1 and 140:1 depending on company size. Independent research finds roughly 28% of agent actions can be traced back to a human sponsor across every environment they touched.

400,000

Non-human identities in the estate

112,000

Of those, traceable to a human sponsor

288,000 unaccounted

Fig. 1 — Agent identities per accountable human role. The ratio that makes per-item review structurally unavailable.

Anatomy of a standing grant

FieldMeaningExample bound
RoleThe accountable human role, not an individual accountClaims Adjudication Lead
Directive classThe class of action permittedAdjudicate claim, value ≤ threshold
Value boundMaximum consequence permitted per action and per period$25,000 per action
Data classWhich classes the action may touchPHI permitted, in-region models only
JurisdictionLegal regimes eligible to processUS only
Temporal boundValidity window and review date90 days, reviewed quarterly
Escalation targetWhere refusals goDirector of Claims Operations
Table 1 — A grant is a structured object, not a permission flag.

Evaluation at execution time

  1. The agent presents a directive with its class, value, data class and target system.
  2. The Role Identity Fabric resolves grants in force for that directive class at that instant.
  3. Each bound is tested. A single failing bound is sufficient to refuse.
  4. On success, the role is attached to the action and carried through routing, boundary and ledger records.
  5. On failure, the action stops and escalates to the grant's escalation target with the failing bound named.

FIG. A02-01

Review after the fact, versus authority before it

Step through the cycle

Lane A — Human-in-the-Loop

  1. 01 Agent plans

    The agent composes an action from context nobody scoped in advance.

  2. 02 Agent acts

    Execution happens against the production system of record.

  3. 03 Reviewer sees a result

    A plausible-looking summary arrives in a queue, on a clock.

  4. 04 Approve or miss

    Under volume, approval becomes the default. Nothing proves scope.

  5. 05 Damage is historical

    The record starts after the fact, if it exists at all.

Lane B — Human-in-the-Role

  1. 01 Directive issued

    A named professional states intent under their own authority.

  2. 02 Role bound

    Role Identity Fabric binds the directive to that authority, cryptographically.

  3. 03 Gates evaluated

    Authority, action and data-boundary gates run in sequence, halting by default.

  4. 04 Action commits

    Only a directive that cleared every gate reaches the system of record.

  5. 05 Evidence written

    The Immutable Audit Ledger records the cycle — including any halt.

Step 1 / 5
Fig. 2 — The same action under review-after-the-fact and under a bounded standing grant.

Why revocation matters more than approval

Approval systems accumulate permissions and rarely shed them, because nothing forces re-examination. A grant carries a temporal bound and a review date, so authority expires by default and must be renewed deliberately. Revocation is immediate and takes effect on the next evaluation, which means withdrawing authority does not require finding and disabling every agent that relied on it.

Role

the unit of accountability

Not the individual, and not the agent

Expiry by default

authority lifecycle

Refuse and escalate

behaviour outside the bounds

Common objections

The first objection is that this is simply role-based access control. It is not: RBAC governs what a principal may reach, while a grant governs what consequence an autonomous action may cause, bounded by value, data class and time, and it is evaluated per directive with the outcome written to evidence. The second objection is that it slows delivery. In practice it moves the conversation earlier — bounds are agreed once, in daylight, rather than negotiated repeatedly under incident pressure.

An approval records that someone clicked. A grant records that someone is answerable. Only one of those survives an inquiry.

Odero Otieno, Founder, CEO & CTO, Dipp AI Technologies

Sources

Sources for every figure in this article.

Where a number comes from Dipp AI's own analysis or an observed deployment, it is labelled as such and is not presented as an independently audited third-party finding.

  1. Dipp AI Technologies, The Enterprise Superintelligence Report, Vol. I (August 2026)

Case studies

Organisations that ran this argument in production.

Modelled reference scenarios with the measurement window, the components enforced and the numbers attached. Each one downloads as a PDF.

Written by Odero Otieno.

Writes the Dipp AI record on enforced governance for agentic systems — authority, enterprise data boundary, cost and compute. Every figure in this piece carries a source, and corrections are published on the record rather than made quietly.