
As AI agents take on more routine work, human involvement shifts toward decisions with greater security, financial, and operational consequences. Approvals, policy exceptions, multi-factor authentication prompts, and unusual behavior still require context and authority that an agent may lack. Mature automation defines which actions can proceed independently, which require review, and which remain outside the agent’s authority.
Effective oversight focuses human attention where judgment materially changes the risk. Clear thresholds, contextual approval requests, and documented escalation paths keep reviewers from becoming bottlenecks while preserving accountability. Menlo Agent Runtime Security supports this model inside the browser sessions where agents interact with applications and data, giving enterprises the visibility and control to expand agent adoption while keeping consequential decisions in responsible hands.
At this point, the odds are good that you’ve used an AI agent or plan to in the near future. Or, there might even be an AI agent working on your behalf at this moment, sending out information and bringing it back to you — guardrails or not.
Either way, here’s what that process typically looks like:
All pretty standard fare. Each step follows an established workflow, allowing the agent to move faster than a person ever could.
However, the process becomes much more complicated when the application presents an unusual login request, the file contains sensitive data, or the transaction exceeds an approval threshold. The agent has now reached a decision with consequences that extend beyond completing the task.
At that point, speed matters less than judgment (aka security). A person needs to understand the context, weigh the risk, and decide whether the action should proceed. As agents take on more routine execution, human involvement shifts toward these less frequent but higher-consequence moments. Human-in-the-loop oversight must be built into the workflow from the beginning, with clear boundaries and intervention points. Waiting until an agent makes the wrong decision leaves the organization responding to an incident that better governance could have prevented.
Traditional workflows often keep people involved at every stage. They review information, approve routine steps, and move work from one system to the next, even when the process follows the same predictable path each time. AI agents can take on much of that execution, completing repeatable actions in line with policies established by the organization.
As routine involvement decreases, the decisions left to people become more consequential. A reviewer may need to interpret the business purpose behind a request, weigh the benefit of an exception against its security risk, or decide whether unusual activity reflects a legitimate change in circumstances. An agent may detect that a request falls outside the normal pattern. It may not understand why the difference matters to the business or who has the authority to accept the risk.
Oversight, therefore, becomes more targeted. People do not need to observe every step an agent takes, but they must be available at defined decision points and receive enough context to act quickly. Each expansion of an agent’s authority should come with equally clear limits. The organization must know which actions the agent can complete, which require approval, and which remain off-limits.
The need for oversight depends on the action an agent is about to take and the consequences of getting that decision wrong. Human involvement becomes especially important when an agent crosses an authorization boundary, encounters an exception, or lacks the context to evaluate the risk.
Agents may prepare transactions, publish content, modify records, send communications, or initiate changes across business systems. Many of these actions can proceed safely within preset limits. Others are difficult to reverse or could create legal, financial, or reputational consequences. And many of these actions are happening at machine-speed, hundreds (at least) times a day. Far too much for an ordinary security team or SOC to keep up with.
With the right tools, organizations can set approval thresholds based on the transaction value, the sensitivity of the affected data, the intended recipient, the application involved, and the ability to undo the action. When a threshold is reached, the reviewer should see what the agent intends to do, why the action is being taken, and which policy or risk triggered the review. That context supports an informed decision and discourages reflexive approval.
Policies provide agents with clear instructions for expected conditions. Business operations, however, regularly produce legitimate requests that fall outside those rules. An agent may need temporary access to restricted data, permission to use an unapproved destination, or additional authority to complete an unusual workflow.
Rejecting every exception can interrupt valid work, while granting exceptions without review exposes the organization to unnecessary risk. A human reviewer can evaluate the business purpose and approve a narrowly defined exception with appropriate limits. Temporary data unmasking follows this model. Sensitive information remains protected by default but can be made visible to an authorized person when a valid business need exists. The exception remains controlled without forcing the business process to stop.
Multi-factor authentication (MFA) prompts are intended to confirm that a legitimate person is behind a sensitive access request. Agents complicate that assumption because they may encounter authentication challenges while operating on someone’s behalf.
The agent should not bypass the identity control or encourage users to approve prompts without understanding them. Instead, the workflow needs a secure handoff. The user should see which application the agent is accessing, why authentication is required, and what action will follow. Human confirmation preserves the purpose of MFA while allowing the agent to resume its work after identity has been verified.
An action may be technically permitted and still appear inconsistent with normal business activity. An agent might access an unfamiliar application, move an unusually large volume of data, change destinations during a task, or attempt an action outside its expected role.
The agent may recognize that something has changed, but the explanation may exist beyond its immediate instructions. A new destination could reflect a legitimate project or a compromised workflow. Human review provides the missing context and gives the organization a chance to stop unusual behavior before it causes damage. However, with most of these ambiguous actions happening outside of a user’s periphery, enterprises must look to tools that leverage artificial intelligence in order to control AI agents — prompting human involvement when flagged.
While human involvement may sound contradictory to automation, when it comes to agents, that’s simply not the case. While human intervention is sometimes treated as evidence that an AI agent lacks sufficient capability, that assumption makes the amount of work completed without people the primary measure of success.
Enterprise automation needs a different standard. The more useful question is whether each decision is being made by the right actor, with the right authority and enough context to understand the consequences.
Organizations already apply this principle across critical business systems:
Together, these controls reduce risk when critical systems are used for consequential work.
Agent governance can follow the same model without sending every action through a manual queue. Routine work can proceed automatically as long as it remains within established policies. When a request is ambiguous or carries greater potential consequences, the workflow can introduce additional checks or route the decision to someone authorized to accept the risk.
This model gives business leaders a stronger foundation for expanding agent adoption. Agents can take on greater responsibility because the organization has already defined where they may act independently, where human judgment enters the workflow, and where their authority ends.
Putting boundaries into practice requires selectivity. If every action requires approval, employees become supervisors for automated workflows, and much of the productivity benefit disappears. Frequent requests also create approval fatigue, making it more likely that people will accept prompts without close examination, or worse, move to shadow solutions.
With the right tools, organizations can avoid that outcome by defining each agent’s authority before deployment, including which applications and data it may access, what it can change or share, and which actions it may complete independently. Those boundaries provide the basis for approval thresholds tied to data sensitivity, action type, destination, and potential business impact. Requests that fall outside those thresholds should follow a clear escalation path to someone with the knowledge and authority to evaluate them. Recording the original request, the reviewer’s decision, and the resulting action gives security and governance teams the observability needed to assess outcomes and refine policies over time.
The quality of the approval experience matters just as much as the threshold that triggered it. A vague prompt that asks someone to “approve agent activity” provides little basis for a responsible decision. The reviewer should see what the agent is attempting, which application or data is involved, why the action requires review, and what will happen if the request is approved or denied.
This context helps people make informed decisions without having to reconstruct the entire workflow. As agents take on new tasks and business processes change, organizations can revisit their thresholds and escalation rules. Human attention remains focused on the decisions where judgment changes the outcome, while routine execution continues without unnecessary interruption.
Policies and approval thresholds only matter if organizations can enforce them where agents work. For many agentic workflows, that place is the browser. Agents use browser sessions to access applications and complete the work that follows, including handling files, entering information, and moving data between services. Each interaction can turn an automated decision into a business action.
Traditional access controls determine whether an agent can enter an application. Once access is granted, security teams still need to govern what the agent does inside the session.
That’s why Menlo Agent Runtime Security (MARS) provides visibility into those interactions and applies enterprise policy as they occur. MARS also protects data via real-time masking when an agent types, copies, uploads, or shares sensitive information, while routing requests for human review when they exceed the agent’s authority. Menlo’s broader content security capabilities flow within the MARS framework so that teams can also inspect and sanitize files before hidden threats reach an endpoint or continue into another workflow.
This session-level context makes human oversight more useful. Reviewers can see the action the agent is attempting, the applications and data involved, and the policy that prompted the escalation. Security teams can use the same visibility to investigate unusual behavior and refine controls as agent workflows change.
Agents can continue performing approved work while MARS applies controls to the specific interactions that introduce risk. This gives CISOs stronger governance over agent activity and gives CIOs a practical path for expanding adoption while maintaining control across enterprise systems.
Schedule a Demo With Us Today to see how we can help you govern AI agents within browser sessions, where their decisions become actions.
Menlo Security
