Which one an operations team actually wants
In-the-loop is right while an agent is new or the work is judgement-heavy: the agent drafts, the person decides. On-the-loop is right once the agent has proven itself on routine cases: it reads, reasons and prepares the write, and the person spends seconds approving rather than minutes doing. Most processes move from the first to the second as trust is earned, and some steps stay in-the-loop forever because the decision is the job.
What both share is that a person can always see what the agent wants to do and why, in plain words, before anything is sent, created or changed.
How tacitrun implements the gate
Every domain agent carries an oversight mode. In-the-loop agents send each decision to the queue. On-the-loop agents run to completion and their writes are held: the platform intercepts the actual call to SendGrid, Salesforce, Shopify or any other connected system, records what would be sent, and waits. The person accepts it as is, modifies the arguments (the corrected version is what executes), or rejects it. A rejected write never reaches the system, and every decision is kept as an audit record and as a learning signal.
The gate lives in the runtime, not in the agent’s instructions. An agent cannot talk itself past it, and an agent that decides not to write does not count as an approval.
The terms, as the product defines them
- Needs your OK
Where your agents ask you to approve, change, or stop something.
Your inbox of decisions an agent has paused on before acting — each shows what it wants to do and why, in plain words. You can approve it, use your own choice instead, or stop it. Risky actions (like sending a message or moving money) always wait here for a human.
- Decision queue
Where domain agents send decisions for a human to approve.
When a domain agent isn't fully autonomous (or hits a high-risk action), it routes the decision to the queue. A human accepts, modifies, or rejects it. Those corrections feed back in as learning signals.
- Runtime oversight
Operational dials (plan mode, context compaction) you can change without re-promoting.
Two governance dials on a domain agent's Spec tab, separate from its behavior contract. Because they tune oversight rather than behavior, saving them does NOT bump the version and is allowed even on a locked production domain agent — so you can tighten or loosen the leash on a live domain agent without a fresh IT approval. Changes apply to in-app runs (Test, Shadow, Eval) immediately; deployed domain agents pick them up on their next deploy.
Questions people ask about this
- Will a domain agent act without my approval?
- No — not by default. A new domain agent only drafts decisions for a human. It can act on its own only after it proves itself in shadow and a human promotes it.
- What’s the decision queue for?
- It’s where domain agents send decisions for a human to approve. Your accept/modify/reject becomes a learning signal.
Related
See it on one of your own processes. Free for the whole product for a trial period, no card needed to start, every write held for your approval.