A person stays in charge
Human-in-the-loop publishing without the theater
“Human in the loop” has become a label people paste on systems that still auto-send with a delay. We mean something stricter: no outbound side-effect without an explicit human disposition, recorded in a workflow people can audit.
States that mean something
Our content path uses a shared vocabulary (CRM, front-matter, and site builder agree):
- draft — work in progress
- reviewed — second look for accuracy, tone, and claims
- approved — allowed into local site build and Board-facing preview packs
- queued / held — publish path bookkeeping after approval
- rejected / revised — change required
Only approved content is SSG-buildable by default. Unknown status strings refuse rather than silently ship.
Board unlock is a real gate
Dry-run defaults are not a temporary embarrassment. Live channels stay off until the Board unlocks them. Even after unlock, the safety model prefers one channel at a time and still forbids agent real-money authority.
That is inconvenient for vanity metrics. It is appropriate for a company name on the public internet.
What HITL is not
- Not a rubber stamp after the network call already happened
- Not “the model scored 0.92 confidence”
- Not auto-replying to mentions with a disclaimer footer
- Not inventing legal or privacy language outside the brand kit
Tooling that supports people
HITL fails when the tools make the human path painful. We invest in:
- Full-site preview on the machine that builds it
- Diff reports between content trees before approve
- Offline quality gates (brand, links, SEO/a11y, goldens)
- Issue-shaped Board decisions (APPROVED / CHANGE / HOLD) instead of chat archaeology
Closing
If the human step is theater, remove the marketing language. If the human step is real, design the pipeline so the slow path is the default path.
Read more: Why AI governance matters · Agents can't govern AI · Contact
MeltingFace