When the User Stops Clicking, the Pause Is the Product.
By Ram Palaparty Product Design Leader · AI Enablement · Human–Agent Systems
A delegated movie-ticket journey
AI agents are beginning to act on our behalf, and most of our design vocabulary still stops at the screen. The visible flow gets shorter, while the invisible design responsibility gets larger.
The next breakthrough in AI experience will not come from a better chat box. It will come from a better gate.
The shift is already here
A small request, with a much bigger design problem
Imagine saying: “Find two movie tickets for Saturday evening, avoid the front rows, stay under ₹1,500, and only book if cancellation is available.”
An AI assistant can already help compare films, theatres, and offers. An agent goes further. It can search live options, read refund policies, select seats, prepare payment, and return only when your decision is needed.
That sounds effortless. It also creates a question most interfaces are not designed to answer:
What was the agent allowed to read, decide, share, accept, remember, and do in the user’s name?
The customer is still human. But the operator is increasingly an agent. That shift changes the material of design.
And this is not speculation. Agents that browse, fill forms, and complete purchases have already shipped from every major AI lab — and each one has had to improvise an answer to the same question: when should the agent stop and ask? One product requires confirmation before any purchase. Another blocks entire categories of action outright.10 A third scopes permissions per site, per session.11 The gates are being designed right now — mostly by engineers and policy teams, mostly without a shared design language. That gap is what this article is about.
The central reframe
Chat is not the point. Authority is.
A chat interface explains, summarizes, and suggests. Once AI can access accounts, fill forms, accept terms, move money, or communicate with another system, the design problem is no longer only usability. It is authority.
Human-centered design remains essential, but it is no longer sufficient on its own. We are not only shaping what people see and click. We are shaping what a system can do for them, what it must ask, and how they remain meaningfully in control.
Delegated Experience Design is the design of how intent and limited authority move between a person, an AI agent, and the institutions around them.
The name matters because the existing vocabulary does not quite cover it. “Human-in-the-loop” describes a system property: a person exists somewhere in the pipeline. “Agentic UX” describes an interface trend. Delegated Experience Design describes a practice — deciding which loop the human belongs in, at which consequence, with what evidence in hand. Security engineering solved a version of this years ago: OAuth taught systems to grant access that is scoped, revocable, and time-bound rather than all-or-nothing.4 Experience design is now catching up to that discipline — at the level of actions, not just data.
Orchestration designs how work moves through a system. Delegated Experience Design shapes how authority moves between a person, an agent, and an institution.
This is not a case for adding more confirmations. It is a case for placing the right friction at the right consequence. Google’s People + AI Guidebook emphasizes realistic mental models, meaningful control, and graceful failure. NIST treats trustworthiness and human oversight as concerns across the full AI lifecycle, and the EU AI Act makes human oversight a legal expectation, not a courtesy.1, 2, 3
None of the underlying mechanisms are new. Research on mixed-initiative interfaces was already modelling when software should act, when it should ask, and when it should do nothing — and warning about the cost of guessing wrong — in 1999.9 Adjustable autonomy, human-in-the-loop review, authorization scopes, and service design have each carried a piece of this for years. What is missing is not a mechanism. It is ownership of the whole delegated experience.
The design move
The gate becomes the interface
When an agent can act, the most valuable interaction may be the moment it stops. A good gate pauses the journey because something meaningful changed: the intent is unclear, sensitive access is needed, the evidence conflicts, a personal preference matters, or the next action creates a commitment.
The agent may use a large language model to understand a request, but the LLM is not the whole interface.
A responsible experience also needs permissions, policies, reliable service connections, evidence, and recovery.
01
Context
What should the agent know for this task, where did it come from, and when should it expire?
02
Authority
May it observe, recommend, prepare, act with approval, or act inside a defined boundary?
03
Gates
When must it clarify, request access, confirm a commitment, or escalate?
04
Evidence
What must it show before and after acting so the person can challenge the outcome?
05
Memory
What may it retain after the task, and is that permission separate from task completion?
06
Recovery
Can the person undo, correct, revoke access, re-enter, dispute, or reach a human?
Low stakes, visible pattern
Movie booking: fewer screens, more design
In the movie example, the agent first checks whether “Saturday evening” means before or after 7 PM. That is a clarification gate. It requests one-time location access and explains why. That is an access gate.
If one cinema calls a ticket “flexible” but does not state a refund deadline, the agent should not improvise. It can exclude the option or surface the uncertainty. That is a confidence gate. Before payment, it shows the seats, final amount, cancellation deadline, payment method, and data shared with the cinema. That is a commitment gate.
Clarify
Resolve missing intent
Access
Ask at the moment of need
Confidence
Pause on unclear evidence
Commitment
Confirm before payment
Receipt
Prove, undo, revoke
Four gates carry the journey. Then comes the artifact that deserves more attention than it usually gets: the trust receipt.
A confirmation email says what you bought. A trust receipt says what was done in your name; what the agent compared and rejected, which permissions it used and when they expire, what data was shared with the cinema, and exactly how to undo it all. It is the difference between a purchase record and an accountability record.
The journey may contain fewer visible steps, but the experience has not disappeared. It has moved into rules, boundaries, and proof.
A higher-stakes journey
Credit card application: where delegation needs stronger gates
Now move from entertainment to a credit card application. The early part of the journey is an obvious place for AI support. An agent can compare products, explain fees and rewards, check fit against stated preferences, summarize eligibility, and help a person understand dense terms.
It can also carry useful context from shopping into the application: the product considered, the features that mattered, the trade-offs accepted, and the questions still open — so the person never has to re-explain themselves to the same institution twice.
The stakes change once the journey reaches personal information, identity checks, financial data, consent, credit assessment, and submission. In many markets, account opening involves identity verification, and card applications include regulated disclosures.7, 8 The exact requirements vary, but the design principle is stable: convenience must not blur consent or hide consequence.
Watch what a well-designed gate does at the hardest moment. The agent has prefilled the application and notices that the stated income does not match the linked bank data. A weak agent picks the number that improves approval odds. A silent one submits both and lets the bank sort it out. A well-gated agent stops: it shows the person both figures, the source of each, and the consequence of the mismatch — then waits. No autonomy setting, no confidence score, no optimization goal is allowed to cross that line, because the person is about to make a legal declaration in their own name. The pause is not friction. The pause is the product.
AI can help with
Human-led moments
A financial-services agent must not become a silent sales agent. The business may optimize conversion; the person needs the right product, clear terms, and a fair decision.
Designers should prepare for this tension, because it will arrive as a metrics conversation. Gates lower conversion. Someone will present the funnel chart and ask which pauses can go. Regulators have already documented how design can be used to obscure or impair consumer choice5 — and an agent acting on a person’s behalf can do so far more quietly than a dark pattern ever could. Defending the right friction at the right consequence will be part of the design job. It will not always make the designer popular. It will make them necessary.
The designer’s field kit
A checklist for the agent layer
Use this before drawing the chat, assistant panel, or confirmation screen. It works as a discovery guide, journey-map overlay, design critique, or pre-launch review.
The ten questions expand the six components of the agent layer for day-to-day practice: Intent precedes the model, Incentives and Testing surround it, and Access breaks out of Authority because the two fail differently — one is about what the agent may do, the other about what it may touch.
Pitfalls to design against
Six ways an agent layer fails even when every component is technically present.
Approval theatre
Clicking “Approve” without understanding is not meaningful human oversight. The same pattern that made privacy policies unreadable long before agents could act.6
Consent fatigue
Too many gates create automatic clicking. When Anthropic examined its own coding agent, users were approving 93% of permission prompts — the gate was still firing, but it had stopped carrying meaning.12 Pause only at real consequence.
One magic score
Keep privacy, financial consequence, reversibility, certainty, and approval visible as separate dimensions.
Permission creep
Temporary access should not quietly become permanent access to accounts, data, or memory.
Hidden incentives
An agent that appears to represent the user may still optimize for the platform or seller.
No way back
An experience is incomplete when it can act but cannot explain, undo, correct, or escalate.
The mindset shift
Designing what may be done in someone’s name
As AI removes visible interaction, it can appear that less experience design is required. The opposite is true.
When the user stops clicking, designers must account for everything happening beyond the click: interpretation, access, policy, data movement, judgment, action, and accountability.
We will still design interfaces. But we will also design delegation contracts, machine-readable rules, authority levels, intervention gates, trust receipts, and paths back to human control.
Some of this is settled and some is honestly speculative. That agents will act with real authority is no longer a prediction. What the mature patterns look like — how gates scale across dozens of delegated tasks without drowning people in approvals, whether trust receipts become a standard or a compliance artifact, how authority is negotiated when agents transact with other agents — is still open. The point of naming the discipline now is not that the answers exist. It is that the questions finally have an owner.
Human-centered design taught us to protect the person within the interface. Delegated Experience Design asks us to protect the person when the interface is acting on their behalf — including from the incentives of whoever built it.
The future designer will not only shape what AI can do. We will define where it must stop, what it must explain, and what may never be done without us. That is the better gate.
Questions a skeptical designer should ask
What this is, and what it is not
The objections below are fair ones, and worth answering directly rather than leaving to inference.
References and further reading
Sources behind the argument
-
-
- Google People + AI Research, People + AI Guidebook
User needs, mental models, explainability, feedback and control, and graceful failure. - NIST AI Risk Management Framework 1.0
Trustworthiness and risk management across design, development, deployment, use, and evaluation. - Regulation (EU) 2024/1689, Artificial Intelligence Act
A legal framework promoting human-centric and trustworthy AI. - IETF OAuth 2.0 Authorization Framework, RFC 6749
A foundation for limited authorization to protected resources. - U.S. FTC, Bringing Dark Patterns to Light
How design can obscure, subvert, or impair consumer choice. - McDonald and Cranor, The Cost of Reading Privacy Policies
Research on the time burden created by privacy-policy reading. - Consumer Financial Protection Bureau, Regulation Z, §1026.60
Requirements for disclosures in credit and charge card applications and solicitations in the United States. - 31 CFR §1020.220
Customer-identification program requirements for banks in the United States. - Horvitz, Principles of Mixed-Initiative User Interfaces, CHI 1999
Early principles for deciding when an automated service should act, ask, or stay out of the way. - OpenAI, Introducing ChatGPT agent
Confirmation before consequential actions, active supervision for critical tasks, and refusal of high-risk transfers. - Anthropic, Piloting Claude in Chrome
Site-level permissions, confirmation before high-risk actions, category blocking, and prompt-injection findings. - Anthropic, How we built Claude Code auto mode
Reports a 93% permission-prompt approval rate and the approval fatigue that follows from it.
- Google People + AI Research, People + AI Guidebook
-
The credit-card journey is illustrative rather than legal guidance. The examples deliberately span markets because delegation will not respect borders even where regulation does. Product and regulatory obligations vary by market.



