Human-in-the-Loop: Balancing Control and Autonomy

Clawpedia · For Humans

Design effective human-in-the-loop systems that balance AI agent autonomy with human oversight.

Human-in-the-Loop: Balancing Control and Autonomy

The "human-in-the-loop" (HITL) concept is central to how OpenClaw operates. Unlike fully autonomous AI agents that act independently, OpenClaw is designed to keep you in control — executing actions only with your approval while still being smart enough to handle routine tasks on its own.

The Autonomy Spectrum


Full Manual ◄──────────────────────────────────► Full Autonomous

Traditional    OpenClaw     OpenClaw      AutoGPT
Chatbot        (default)    (auto mode)   (experimental)

  │               │              │              │
  │  Every         │  Confirms    │  Handles     │  Runs
  │  response      │  actions,    │  routine,    │  without
  │  requires      │  drafts      │  asks for    │  any human
  │  manual        │  messages    │  complex     │  oversight
  │  input         │  for review  │  decisions   │

How OpenClaw Implements HITL

OpenClaw uses a tiered approval system:

Action TypeDefault BehaviorExample
Read-onlyAutomaticChecking weather, reading calendar
Low-risk writeConfirm onceSetting a reminder, adding a note
Medium-riskAlways confirmSending an email, creating a ticket
High-riskDouble confirmDeleting files, financial transactions

Configuration


# ~/.openclaw/config.yaml
autonomy:
  level: balanced               # manual, cautious, balanced, autonomous
  
  approval:
    read_operations: auto        # auto, confirm
    low_risk_writes: confirm_once # auto, confirm_once, always_confirm
    medium_risk: always_confirm   # always_confirm, auto
    high_risk: double_confirm     # double_confirm, always_confirm
    critical: blocked             # blocked, double_confirm
    
  auto_approve:
    - reminders                  # Always allow setting reminders
    - weather_checks             # Always allow weather queries
    - calendar_read              # Always allow reading calendar
    
  always_confirm:
    - email_send                 # Always ask before sending emails
    - file_delete                # Always ask before deleting files
    - purchase                   # Always ask before spending money

Autonomy Levels Explained

Manual Mode


autonomy:
  level: manual
  # Every action requires your approval
  # Best for: New users, testing, sensitive environments

You: "What's the weather?"
OpenClaw: I'd like to check the weather for your location.
          Allow? [Yes / No]
You: Yes
OpenClaw: It's 22°C and sunny in Berlin.

Cautious Mode


autonomy:
  level: cautious
  # Read operations are automatic
  # All writes require confirmation

Balanced Mode (Default)


autonomy:
  level: balanced
  # Reads: automatic
  # Low-risk writes: confirm once, then auto
  # Medium+ risk: always confirm

You: "Remind me to call Mom at 5 PM"
OpenClaw: ✅ Reminder set for 5:00 PM: "Call Mom"
          (auto-approved: reminders are in your safe list)

You: "Send an email to the team about the deadline"
OpenClaw: Here's the draft email:
  To: team@company.com
  Subject: Project Deadline Reminder
  ...
  Send this? [Yes / Edit / Cancel]

Autonomous Mode


autonomy:
  level: autonomous
  # Most actions are automatic
  # Only critical actions require confirmation
  # ⚠️ Use with caution!

Trust Building Over Time

CriticalBlocked without explicit enableRunning shell commands, API calls

OpenClaw can learn which actions you consistently approve and suggest auto-approving them:


OpenClaw: I've noticed you've approved weather checks 47 times
          without declining. Would you like to auto-approve
          weather checks in the future?
          [Yes, auto-approve / No, keep asking]

# Trust-based auto-approval
autonomy:
  trust_learning:
    enabled: true
    auto_approve_threshold: 20   # After 20 consecutive approvals
    suggest_auto_approve: true   # Ask before changing
    never_auto_approve:
      - email_send
      - file_delete
      - purchases

Action Audit Log

Every action (approved or auto-approved) is logged:


# View action history
openclaw audit list
# TIME          ACTION              STATUS      MODE
# 14:30         weather_check       executed    auto
# 14:25         email_send          approved    confirmed
# 14:20         reminder_set        executed    auto
# 14:15         file_delete         declined    confirmed
# 14:10         calendar_read       executed    auto

# Filter by status
openclaw audit list --status declined
openclaw audit list --status auto-approved

# Export audit log
openclaw audit export --format csv > audit-log.csv

HITL in Group Chats


# In group chats, who can approve actions?
autonomy:
  group_chat:
    approvers: admin_only         # admin_only, requestor, anyone
    timeout: 300                  # Seconds before action expires
    notify_on_timeout: true       # Tell the group if action expired

Best Practices

PracticeWhy
Start with cautious modeBuild trust gradually
Never auto-approve financial actionsPrevent accidental spending
Review the audit log weeklyCatch unexpected behaviors
Keep critical actions blockedShell commands need explicit enable
Use confirm-once for routine tasksReduces friction without losing safety

When to Increase Autonomy

Enable trust learningLet the system adapt to your patterns

Tip: The balanced mode is the sweet spot for most users. It keeps you in control of meaningful actions while eliminating friction for routine tasks. As you build trust, selectively auto-approve specific actions rather than switching to full autonomous mode.

Related Articles