DEV Community

Discussion on: I Built an Agent to Run Live Event Raffles (then tried to rig it)

Collapse
 
valentin_monteiro profile image
Valentin Monteiro

The fact that the human approved the delete without hesitation is the most valuable part of this demo. Most people sell HITL as the safety net. You proved it's not. Programmatic policies are the actual guardrail, the human is just a speed bump.

Collapse
 
kimmaida profile image
Kim Maida

Consent fatigue and --dangerously-skip-permissions are powerful things that show how much a person cannot be the only gate. Especially when we historically have strict authorization in place for human users. If we assume the human is the final authorization for the machine, we go right back to just having a human who has too many permissions... which was a problem we already solved before (with governance and policy).