When Your AI Agent Should Ask a Human
A useful interruption gives you a decision you can make. A fictional CSV importer shows when an agent should investigate, ask, prepare or wait.
· The Tellenze team
“Should I continue?”
The question arrives halfway through the work. You open the conversation, scroll back, and try to work out what saying yes would mean.
In a fictional software team, an agent is adding a CSV importer to an equipment register, with a preview before anything is saved. The brief says that when an equipment code appears twice, it should keep the latest entry. The sample file has two rows for A17, with different storage locations. Neither row has a date.
The agent could make the last row win. It could ask which CSV library to use. Or it could bring the team the question hiding inside “latest.”
Those choices would produce very different interruptions.
What would the answer change?
Before asking, the agent has some work of its own to do. It can inspect existing imports, read the relevant tests and check whether the file contains a timestamp under another name. It can look for a convention already established in the project.
If the repository has a supported CSV reader, choosing it may be an ordinary implementation decision. Asking the product owner to choose a library would pull them into work the agent was meant to handle.
The duplicate equipment code is different. Suppose the existing guidance says nothing about ordering. A row near the bottom might be newer, or someone might simply have sorted the spreadsheet. More inspection won't reveal the intention of the person exporting it.
Now a question can expose the actual choice:
The sample file gives A17 two storage locations and no timestamp. Should the last row replace the earlier one, or should the preview flag the conflict for the person importing it? I recommend flagging it, because row order doesn't establish which location is current. I can finish the valid-row preview while this is unresolved.
The recommendation is contestable. Perhaps this particular export always puts updates last, and the owner can explain that. Perhaps a collision should prevent the whole import. The question invites an answer that changes the behavior.
A generic “Continue?” does much less. It asks the person to reconstruct the issue before they can decide.
Anthropic's April 2026 discussion of trustworthy agents distinguishes gaps an agent can investigate from questions of preference or intent that only the user can settle. It also describes the friction of repeated permission prompts. This is a vendor's account of its design choices, rather than proof that an agent will recognize every boundary correctly.
For our team, the useful test is simple: can we explain what would be done differently after the person answers?
Several problems can sound like a permission question
“I need your input” can hide a missing fact, a product choice, an action requiring approval, or a tool that isn't working. Treating all four as “May I proceed?” makes the conversation harder than it needs to be.
Here is a practical distinction for the fictional importer:
| What the agent encounters | What it should do next | What the person needs to see |
|---|---|---|
| It doesn't know which CSV reader the project uses. | Inspect the existing implementation and documentation within its allowed access. | Usually no question; report a real discovery gap if inspection cannot settle it. |
| “Latest” could mean file order or a timestamp that isn't present. | Ask which behavior the importer should promise. | The conflicting rows, the viable interpretations and the effect of each. |
| The requested next step would modify the live equipment register, outside its granted authority. | Prepare the proposed change and request the required approval before applying it. | The target environment, affected records, exact change and relevant checks. |
| It cannot access the test service. | Explain the access failure and which verification remains unavailable. | The failed capability and the concrete next action; a yes cannot supply missing access. |
These are starting points, not a universal permission policy. The team's actual access rules and approval requirements still govern the work.
An explicitly authorized action doesn't become unauthorized just because it matters. Equally, being easy to undo doesn't make an action permitted. A local experiment may be within the brief; sending its output to a customer may require a separate decision.
The agent should apply the authority it has and ask for the particular authority it lacks. The reader shouldn't have to guess which kind of answer is being requested.
A pause needn't freeze everything
The equipment-code decision affects one branch of the importer. It needn't prevent the agent from checking headers, handling malformed files or building the already agreed preview for unambiguous rows.
There is a limit here. Those tasks must actually be independent of the unresolved behavior and already within scope. If choosing a collision policy determines the entire data model, preparing more implementation might create work that will be thrown away. In that case, a pause is sensible.
The 2019 Guidelines for Human-AI Interaction paper, by Saleema Amershi and colleagues, includes disambiguation and narrowing the service when the user's goals are uncertain. That offers more room than a binary choice between guessing and doing nothing. Its evaluation concerned design guidance across AI-infused products; it didn't test today's coding agents.
In this example, the agent can deliver a valid-row preview and leave conflicting rows unresolved. It should say so plainly. A polished screen that silently drops the second A17 would disguise the very decision the team hasn't made.
This is also where “I'll wait” needs a real meaning. Which operation is paused? What preparation is complete? What will resume after the answer? If nobody replies today, the records should remain uncommitted, and the unfinished behavior should remain visible.
Let the person change the proposal
Sometimes the right answer is neither of the agent's suggested options.
The equipment owner might say, “Keep both rows in the preview. Let the person importing the file choose the location, and don't save anything until every conflict is resolved.”
That's more than approval. It changes the proposal. The agent needs to reflect that answer in the behavior and its checks, rather than interpret it as a yes to the original plan.
LangChain's current human-in-the-loop documentation shows mechanisms for pausing configured actions and resuming with approval, edits or rejection, while retaining execution state. A framework can support the pause. It can't decide whether the person saw enough information to make a useful choice.
A consequential approval request therefore needs something inspectable. “Apply the import?” should lead to the reviewed preview, identify the environment and make clear what will change. If the proposal changes materially after review, that earlier approval may no longer cover it.
For the agent's next question, try a short draft with four parts:
I found: the specific evidence that raised this question.
Your answer changes: the behavior or commitment at stake.
My proposal: a concrete next action, with the reason and relevant limit.
While this waits: what can continue, what is paused and what remains untouched.
Keep it shorter when the choice is small. A preference between two harmless headings doesn't need a miniature report.
Back at the equipment register, the owner can now answer the collision question without choosing a parser, reading a stack trace or wondering whether the live records have already changed.
The agent still has plenty of work to finish. The person has one decision they can actually make.
Further reading
- Trustworthy agents in practice — Anthropic, April 2026 — the tension between useful autonomy, repeated prompts and questions only a user can settle.
- Guidelines for Human-AI Interaction — Saleema Amershi and colleagues, CHI 2019 — interaction guidance on uncertainty, disambiguation, correction and control.
- Human-in-the-loop — LangChain documentation — the mechanics of pausing actions and resuming after a human decision.