
Human approval for agent actions: when to ask and how
Some actions should not be an agent's decision alone. How to pick them, and how to design approval requests that people actually read before they answer.
4 posts

Some actions should not be an agent's decision alone. How to pick them, and how to design approval requests that people actually read before they answer.

How passkeys work under WebAuthn, the difference between synced and device-bound passkeys, and a rollout plan that covers fallback and recovery from day one.

Recovery is the weakest door into most accounts. Design rules for a recovery email that helps a locked-out person without handing an attacker a second way in.

Step-up authentication asks for a stronger or fresher factor only before sensitive actions. Which actions to cover, how fresh a session must be, and how to avoid MFA fatigue.