When the User Stops Clicking, the Pause Is the Product.

By Ram Palaparty Product Design Leader · AI Enablement · Human–Agent Systems

A person delegates a movie-ticket task to an AI agent that compares options, reads policies, chooses seats, and asks before booking.

A delegated movie-ticket journey

AI agents are beginning to act on our behalf, and most of our design vocabulary still stops at the screen. The visible flow gets shorter, while the invisible design responsibility gets larger.

The next breakthrough in AI experience will not come from a better chat box. It will come from a better gate.

The shift is already here

A small request, with a much bigger design problem

Imagine saying: “Find two movie tickets for Saturday evening, avoid the front rows, stay under ₹1,500, and only book if cancellation is available.”

An AI assistant can already help compare films, theatres, and offers. An agent goes further. It can search live options, read refund policies, select seats, prepare payment, and return only when your decision is needed.

That sounds effortless. It also creates a question most interfaces are not designed to answer:

What was the agent allowed to read, decide, share, accept, remember, and do in the user’s name?

The customer is still human. But the operator is increasingly an agent. That shift changes the material of design.

And this is not speculation. Agents that browse, fill forms, and complete purchases have already shipped from every major AI lab — and each one has had to improvise an answer to the same question: when should the agent stop and ask? One product requires confirmation before any purchase. Another blocks entire categories of action outright.10 A third scopes permissions per site, per session.11 The gates are being designed right now — mostly by engineers and policy teams, mostly without a shared design language. That gap is what this article is about.

The central reframe

Chat is not the point. Authority is.

A chat interface explains, summarizes, and suggests. Once AI can access accounts, fill forms, accept terms, move money, or communicate with another system, the design problem is no longer only usability. It is authority.

Human-centered design remains essential, but it is no longer sufficient on its own. We are not only shaping what people see and click. We are shaping what a system can do for them, what it must ask, and how they remain meaningfully in control.

Delegated Experience Design is the design of how intent and limited authority move between a person, an AI agent, and the institutions around them.

The name matters because the existing vocabulary does not quite cover it. “Human-in-the-loop” describes a system property: a person exists somewhere in the pipeline. “Agentic UX” describes an interface trend. Delegated Experience Design describes a practice — deciding which loop the human belongs in, at which consequence, with what evidence in hand. Security engineering solved a version of this years ago: OAuth taught systems to grant access that is scoped, revocable, and time-bound rather than all-or-nothing.4 Experience design is now catching up to that discipline — at the level of actions, not just data.

Orchestration designs how work moves through a system. Delegated Experience Design shapes how authority moves between a person, an agent, and an institution.

This is not a case for adding more confirmations. It is a case for placing the right friction at the right consequence. Google’s People + AI Guidebook emphasizes realistic mental models, meaningful control, and graceful failure. NIST treats trustworthiness and human oversight as concerns across the full AI lifecycle, and the EU AI Act makes human oversight a legal expectation, not a courtesy.1, 2, 3

None of the underlying mechanisms are new. Research on mixed-initiative interfaces was already modelling when software should act, when it should ask, and when it should do nothing — and warning about the cost of guessing wrong — in 1999.9 Adjustable autonomy, human-in-the-loop review, authorization scopes, and service design have each carried a piece of this for years. What is missing is not a mechanism. It is ownership of the whole delegated experience.

The design move

The gate becomes the interface

When an agent can act, the most valuable interaction may be the moment it stops. A good gate pauses the journey because something meaningful changed: the intent is unclear, sensitive access is needed, the evidence conflicts, a personal preference matters, or the next action creates a commitment.

Framework showing Context, Authority, Gates, Evidence, Memory, and five meaningful gate types.

The agent layer is not just a prompt. It combines context, permissions, gates, evidence, memory, and recovery.

The agent may use a large language model to understand a request, but the LLM is not the whole interface.

A responsible experience also needs permissions, policies, reliable service connections, evidence, and recovery.

01

Context

What should the agent know for this task, where did it come from, and when should it expire?

02

Authority

May it observe, recommend, prepare, act with approval, or act inside a defined boundary?

03

Gates

When must it clarify, request access, confirm a commitment, or escalate?

04

Evidence

What must it show before and after acting so the person can challenge the outcome?

05

Memory

What may it retain after the task, and is that permission separate from task completion?

06

Recovery

Can the person undo, correct, revoke access, re-enter, dispute, or reach a human?

Low stakes, visible pattern

Movie booking: fewer screens, more design

In the movie example, the agent first checks whether “Saturday evening” means before or after 7 PM. That is a clarification gate. It requests one-time location access and explains why. That is an access gate.

If one cinema calls a ticket “flexible” but does not state a refund deadline, the agent should not improvise. It can exclude the option or surface the uncertainty. That is a confidence gate. Before payment, it shows the seats, final amount, cancellation deadline, payment method, and data shared with the cinema. That is a commitment gate.

Clarify

Resolve missing intent

Access

Ask at the moment of need

Confidence

Pause on unclear evidence

Commitment

Confirm before payment

Receipt

Prove, undo, revoke

Four gates carry the journey. Then comes the artifact that deserves more attention than it usually gets: the trust receipt.

A confirmation email says what you bought. A trust receipt says what was done in your name; what the agent compared and rejected, which permissions it used and when they expire, what data was shared with the cinema, and exactly how to undo it all. It is the difference between a purchase record and an accountability record.

The journey may contain fewer visible steps, but the experience has not disappeared. It has moved into rules, boundaries, and proof.

A higher-stakes journey

Credit card application: where delegation needs stronger gates

Now move from entertainment to a credit card application. The early part of the journey is an obvious place for AI support. An agent can compare products, explain fees and rewards, check fit against stated preferences, summarize eligibility, and help a person understand dense terms.

It can also carry useful context from shopping into the application: the product considered, the features that mattered, the trade-offs accepted, and the questions still open — so the person never has to re-explain themselves to the same institution twice.

Credit card application journey showing where AI can assist and where stronger human gates are needed.

Help can be broad during comparison and preparation. Human control must become stronger as the journey reaches identity, financial data, consent, and submission.

The stakes change once the journey reaches personal information, identity checks, financial data, consent, credit assessment, and submission. In many markets, account opening involves identity verification, and card applications include regulated disclosures.7, 8 The exact requirements vary, but the design principle is stable: convenience must not blur consent or hide consequence.

Watch what a well-designed gate does at the hardest moment. The agent has prefilled the application and notices that the stated income does not match the linked bank data. A weak agent picks the number that improves approval odds. A silent one submits both and lets the bank sort it out. A well-gated agent stops: it shows the person both figures, the source of each, and the consequence of the mismatch — then waits. No autonomy setting, no confidence score, no optimization goal is allowed to cross that line, because the person is about to make a legal declaration in their own name. The pause is not friction. The pause is the product.

Five gates for a credit card application: personal information, verification, consent, submission, and recovery.

Stronger gates protect personal information, verification access, consent, submission, and recovery.

AI can help with

  • Comparing cards against the applicant’s priorities, not only the issuer’s acquisition goals.

  • Explaining fees, rewards, eligibility, and trade-offs in plain language.

  • Prefilling known information while separating verified, user-provided, and inferred data.

  • Summarizing terms against preferences and linking each interpretation to the original disclosure.

  • Preparing the application and identifying missing information without silently submitting it.

Human-led moments

  • Granting access to identity, income, bank, or other sensitive information.

  • Resolving policy exceptions, conflicting information, or uncertain eligibility.

  • Accepting disclosures and giving final consent.

  • Authorizing a credit check or application submission.

  • Choosing whether optional information and preferences may be remembered.

A financial-services agent must not become a silent sales agent. The business may optimize conversion; the person needs the right product, clear terms, and a fair decision.

Designers should prepare for this tension, because it will arrive as a metrics conversation. Gates lower conversion. Someone will present the funnel chart and ask which pauses can go. Regulators have already documented how design can be used to obscure or impair consumer choice5 — and an agent acting on a person’s behalf can do so far more quietly than a dark pattern ever could. Defending the right friction at the right consequence will be part of the design job. It will not always make the designer popular. It will make them necessary.

The designer’s field kit

A checklist for the agent layer

Use this before drawing the chat, assistant panel, or confirmation screen. It works as a discovery guide, journey-map overlay, design critique, or pre-launch review.

The ten questions expand the six components of the agent layer for day-to-day practice: Intent precedes the model, Incentives and Testing surround it, and Access breaks out of Authority because the two fail differently — one is about what the agent may do, the other about what it may touch.

  • 1 · Intent — Is the outcome specific enough to act on? What must be clarified? What may never be inferred?

  • 2 · Context — What does the agent need now? What is verified, provided, or inferred? Is every source fresh and relevant?

  • 3 · Authority — Can it read, recommend, prepare, submit, purchase, communicate, or represent? What are the limits?

  • 4 · Access — Is permission requested at the moment of need? Is it narrow, understandable, revocable, and time-bound?

  • 5 · Gates — Where do ambiguity, sensitive data, judgment, commitment, irreversibility, or low confidence require a pause?

  • 6 · Evidence — Can the person see what the agent used, chose, shared, could not verify, and what happens next?

  • 7 · Recovery — Can people edit, undo, cancel, re-enter, dispute, revoke, or escalate without starting over?

  • 8 · Memory — Is remembering separate from completing the task? Can people inspect, correct, delete, or expire context?

  • 9 · Incentives — Whose objective is being optimized: the user’s, platform’s, advertiser’s, employer’s, or seller’s?

  • 10 · Testing — Did users understand the action, its consequence, and the control they still retained? Did it stop whenever it truly needed to? Did it avoid stopping when nothing meaningful had changed?

Pitfalls to design against

Six ways an agent layer fails even when every component is technically present.

Approval theatre

Clicking “Approve” without understanding is not meaningful human oversight. The same pattern that made privacy policies unreadable long before agents could act.6

Consent fatigue

Too many gates create automatic clicking. When Anthropic examined its own coding agent, users were approving 93% of permission prompts — the gate was still firing, but it had stopped carrying meaning.12 Pause only at real consequence.

One magic score

Keep privacy, financial consequence, reversibility, certainty, and approval visible as separate dimensions.

Permission creep

Temporary access should not quietly become permanent access to accounts, data, or memory.

Hidden incentives

An agent that appears to represent the user may still optimize for the platform or seller.

No way back

An experience is incomplete when it can act but cannot explain, undo, correct, or escalate.

The mindset shift

Designing what may be done in someone’s name

As AI removes visible interaction, it can appear that less experience design is required. The opposite is true.

When the user stops clicking, designers must account for everything happening beyond the click: interpretation, access, policy, data movement, judgment, action, and accountability.

We will still design interfaces. But we will also design delegation contracts, machine-readable rules, authority levels, intervention gates, trust receipts, and paths back to human control.

Some of this is settled and some is honestly speculative. That agents will act with real authority is no longer a prediction. What the mature patterns look like — how gates scale across dozens of delegated tasks without drowning people in approvals, whether trust receipts become a standard or a compliance artifact, how authority is negotiated when agents transact with other agents — is still open. The point of naming the discipline now is not that the answers exist. It is that the questions finally have an owner.

Human-centered design taught us to protect the person within the interface. Delegated Experience Design asks us to protect the person when the interface is acting on their behalf — including from the incentives of whoever built it.

The future designer will not only shape what AI can do. We will define where it must stop, what it must explain, and what may never be done without us. That is the better gate.

Questions a skeptical designer should ask

What this is, and what it is not

The objections below are fair ones, and worth answering directly rather than leaving to inference.

Human-in-the-loop says a person can participate in the workflow. Delegated Experience Design decides where that participation is meaningful: which authority is changing, what the person must understand before it changes, and what rights they still hold afterwards. HITL is the mechanism. This is the judgment about when and why to use it.

Orchestration coordinates execution. Delegated Experience Design governs the relationship around execution, so an orchestrator is one implementation detail inside it. The clearest test: a single simple agent can deliver an excellent delegated experience, and a sophisticated multi-agent orchestrator can deliver a terrible one.

Not necessarily. A set of options can still conceal the alternatives that were omitted, the commercial incentive behind the default, the evidence that was uncertain, and the permission that quietly widens when one is chosen. Choice is not the same thing as informed authority.

Consent is one gate among several. Delegation also covers intent, context, authority, execution, evidence, memory, incentives, and recovery — most of which happen long before or well after the moment someone taps “Allow.”

Sometimes, deliberately. The goal is neither maximum autonomy nor maximum confirmation, but meaningful friction at meaningful consequence. A gate that fires everywhere teaches people to ignore it, which is worse than having no gate at all.

Test whether people understood the action and its consequence, whether the agent stayed inside the authority it was granted, and whether the action could be challenged or reversed afterwards. A click on “Approve” is not proof of understanding.

References and further reading

Sources behind the argument

      1. Google People + AI Research, People + AI Guidebook
        User needs, mental models, explainability, feedback and control, and graceful failure.
      2. NIST AI Risk Management Framework 1.0
        Trustworthiness and risk management across design, development, deployment, use, and evaluation.
      3. Regulation (EU) 2024/1689, Artificial Intelligence Act
        A legal framework promoting human-centric and trustworthy AI.
      4. IETF OAuth 2.0 Authorization Framework, RFC 6749
        A foundation for limited authorization to protected resources.
      5. U.S. FTC, Bringing Dark Patterns to Light
        How design can obscure, subvert, or impair consumer choice.
      6. McDonald and Cranor, The Cost of Reading Privacy Policies
        Research on the time burden created by privacy-policy reading.
      7. Consumer Financial Protection Bureau, Regulation Z, §1026.60
        Requirements for disclosures in credit and charge card applications and solicitations in the United States.
      8. 31 CFR §1020.220
        Customer-identification program requirements for banks in the United States.
      9. Horvitz, Principles of Mixed-Initiative User Interfaces, CHI 1999
        Early principles for deciding when an automated service should act, ask, or stay out of the way.
      10. OpenAI, Introducing ChatGPT agent
        Confirmation before consequential actions, active supervision for critical tasks, and refusal of high-risk transfers.
      11. Anthropic, Piloting Claude in Chrome
        Site-level permissions, confirmation before high-risk actions, category blocking, and prompt-injection findings.
      12. Anthropic, How we built Claude Code auto mode
        Reports a 93% permission-prompt approval rate and the approval fatigue that follows from it.

The credit-card journey is illustrative rather than legal guidance. The examples deliberately span markets because delegation will not respect borders even where regulation does. Product and regulatory obligations vary by market.