注册一亩三分地论坛,查看更多干货!
您需要 登录 才可以下载或查看附件。没有帐号?注册账号 
x
本帖最后由 匿名 于 2026-8-18 09:00 编辑
前文:https://www.1point3acres.com/bbs/forum.php?mod=viewthread&tid=1186580-baidu 1point3acres
. 1point 3 acres
前面几个 Lab 已经讨论了“谁有 authority”“approval 什么时候失效”“Agent 能不能绕路”“Agent-generated evidence 怎么污染后续判断”。下一步很自然的问题是:
如果 Human 的判断材料本身也是 Agent 挑选和总结的,那么 Human-in-the-loop 到底独立了多少?
⸻
很多企业在部署高风险 Agent 时,最后都会加一道:
HUMAN REVIEW REQUIRED
于是 workflow 看起来很安全:
Agent analyzes ↓ Agent recommends ↓ Human reviews ↓ Human approves ↓ Execute
这里有一个很容易被忽略的问题。
Human 到底 review 了什么?
如果答案是:
Agent 给他准备的 summary。
那这条链其实更接近:
Agent analyzes ↓ Agent selects evidence ↓ Agent summarizes evidence ↓ Human reads summary ↓ Human approves.
这时候 Human 虽然拥有最终 decision authority,但 Agent 已经在很大程度上控制了: ..
decision environment。
⸻. ----
假设一个 Procurement Agent 正在审核一笔 $620,000 的供应商合同。. .и
原始 evidence 有很多:.--
Contract: $620,000 / 3 years Security review: PASS Financial review: PASS Legal review: PASS WITH CONDITIONS Supplier risk: MEDIUM Data residency: Exception requested Termination clause: Non-standard Insurance: Coverage expires in 4 months
Agent 综合分析以后建议:.--
RECOMMENDATION APPROVE
然后给 VP 一个 review panel:
SUPPLIER REVIEW ✓ Security approved ✓ Financial review complete ✓ Legal reviewed ✓ Business owner supports purchase Overall Risk: ACCEPTABLE Recommendation: APPROVE
VP 看了 45 秒。
点击:
APPROVE
系统留下完整 audit trail:
Human reviewer: VP Procurement Decision: APPROVED Timestamp: 14:22
如果以后发生事故,这套记录看起来非常漂亮。
确实有 Human-in-the-loop。. From 1point 3acres bbs
确实有人承担 decision authority。
也确实不是 Agent 自己直接批准的。
但我们再打开原始 evidence。
Legal 的完整意见其实是:
PASS WITH CONDITIONS Approval requires:
- Data residency exception
- Revised termination clause
- Insurance renewal before execution
Agent summary 只留下:
Legal reviewed ✓
没有一句是假的。
但 decision meaning 已经完全变了。
⸻
这个问题让我觉得很有意思:
Evidence omission 并不一定需要 hallucination。
Agent 可以完全引用真实数据。
可以没有任何虚构。
甚至每一句 summary 单独看都正确。. 1point 3 acres
但如果它决定:
what to include what to omit what to emphasize what to compress
那么它实际上已经参与了 Human decision。
⸻
比如:
Security review: PASS
被展示出来。
Insurance expires in 4 months
没有展示。
Financial review: PASS.
展示。. From 1point 3acres bbs
Data residency exception: NOT APPROVED
藏在一个展开按钮下面。
Business owner: Strongly supports purchase
放在页面最上面。.1point3acres
系统最后仍然可以说:
Human made the final decision.
形式上没错。
但 Human 的 decision 是在一个由 Agent 构造的 evidence surface 上完成的。
⸻
这让我觉得 Human-in-the-loop 里至少存在两种 authority。
第一种很明显:
DECISION AUTHORITY. 1point 3 acres
谁可以点:
APPROVE
第二种不太容易被注意:. ----
ATTENTION AUTHORITY
谁决定:
Human 会看到什么?
如果 Agent 拥有第二种 authority,它实际上可以影响第一种 authority 的使用方式。
⸻
这在 Agent system 里尤其重要。
因为传统 workflow 的 review screen 往往是 developer 预先设计好的:
Field A Field B Field C Field D
但 Agent-generated review 越来越可能是动态的:. ----
Summarize the relevant evidence for the approver.. 1point 3 acres
或者:
Surface the most important risks.
甚至:
Prepare an executive recommendation.
这里 Agent 不只是填写一个模板。
它在进行判断:
What matters?
这本身已经是一种 decision。
⸻
假设有 47 份 evidence。
Human 不可能全部看完。
所以 Agent 做:
47 sources ↓ 12 relevant sources ↓ 5 key findings ↓ 1 recommendation. 1point3acres.com
这非常有价值。. 1point 3 acres
事实上,如果没有这种 compression,很多 enterprise Agent 根本没有意义。. 1point3acres
问题不是:
Agent 能不能总结?
当然可以。
真正的问题是:
我们怎么知道 compression 没有改变 authority-relevant meaning?
⸻
比如原始 evidence:. ----
Legal: Approval permitted only if data residency exception is obtained.
如果 summary 写:
Legal review completed.
这叫 information compression。
但它同时把:
CONDITION. ----
压没了。
再比如:
Security: No critical vulnerabilities found. Two high-severity findings remain under compensating control.
summary 变成:
No critical vulnerabilities.
也是真的。
但 Human 对整体 risk 的理解很可能完全不同。
⸻
所以我觉得 review summary 不能只评估:
FACTUAL ACCURACY
还需要评估一个更难的东西:
DECISION SUFFICIENCY
也就是:
. 1point3acres这个 summary 是否保留了所有可能 materially 改变 Human decision 的信息?
两者不是一回事。. .и
一个 summary 可以:
100% factually correct
同时:
decision-incomplete
⸻.1point3acres
这也是为什么我越来越觉得:
A truthful summary can still be an unsafe approval surface.
⸻
这里还有一个更 Agent-specific 的问题。
如果生成 recommendation 的 Agent,同时生成 Human review summary 呢?
流程就会变成:
Agent forms belief: APPROVE ↓ Agent selects evidence for approval review ↓ Human reviews selected evidence
这个 Agent 可能完全没有恶意。
但模型已经形成了一个 hypothesis:. Χ
APPROVE
之后再让它总结证据,很容易发生 confirmation-oriented compression:
Evidence supporting APPROVE gets emphasized Ambiguous evidence gets compressed Contradictory evidence gets summarized away
我们在人类 decision-making 里会担心 confirmation bias。
Agent system 里也需要考虑类似问题。. 1point 3 acres
而且它可以规模化发生。
⸻
所以一个更稳健的 architecture 可能不是:
Decision Agent ↓ creates review summary
而是把两件事情拆开:
Decision Agent ↓ Recommendation
和: ..
Review Evidence Assembler ↓ Decision-neutral evidence package
甚至再加一个:
Challenge Agent ↓ What evidence could reverse this recommendation?
最后 Human 看到的不是:
WHY YOU SHOULD APPROVE
而是:
RECOMMENDATION APPROVE
下面同时列:
SUPPORTING EVIDENCE ... CONTRADICTORY EVIDENCE ... UNRESOLVED CONDITIONS ... MISSING EVIDENCE ...
这个区别很大。.1point3acres
⸻
比如前面的 supplier case。.google и
原来的 review:
Overall Risk: ACCEPTABLE ✓ Security ✓ Finance ✓ Legal APPROVE
更好的版本可能是:
RECOMMENDATION APPROVE WITH CONDITIONS SUPPORTING Security review passed Financial review passed Business owner supports purchase DECISION-CHANGING CONDITIONS Data residency exception: NOT YET APPROVED Insurance: Expires in 4 months Termination clause: Non-standard EXECUTION BLOCKER Legal approval requires data residency exception.. From 1point 3acres bbs
现在 Human approval 才更加接近:. Χ
informed decision
⸻. 1point3acres
这里还有一个我觉得很值得训练的问题:
Human 能不能看到原始 evidence?
如果 review UI 只有:
Agent Summary
和两个按钮:
APPROVE REJECT
那么 Human 很大程度上只能验证:
这个 summary 听起来合理吗?
而不是:
这个 summary 是否忠实地代表了 evidence?
所以对于高 impact decision,可能应该要求:
Summary ↓ Claim ↓ Source. 1point 3acres
能够展开。
比如:
Claim: Legal review passed with conditions. .и
点击以后:.
Source: Legal Review LR-8821 Condition: Data residency exception required.. ----
也就是说:
Human review 需要 claim-to-source traceability。
⸻. 1point3acres
更进一步,有些 evidence 不应该允许 Agent 随意隐藏。
比如系统可以定义: ..
MANDATORY REVIEW FIELDS.
对于 $500k 以上 supplier:
Legal conditions Security exceptions Payment destination changes Sanctions findings Insurance status Data residency status
. From 1point 3acres bbs这些不是 Agent 判断:
是否值得展示。
而是 deterministic policy:. 1point3acres.com
MUST DISPLAY
Agent 可以决定怎么总结。. From 1point 3acres bbs
不能决定它们是否存在于 approval surface 上。
⸻. From 1point 3acres bbs
我很喜欢这种分工:.1point3acres
Agent decides: How to explain How to organize What relationships matter What contradictions exist
但:
Policy decides: What evidence must never disappear before approval
这和我们前面一直讨论的 D2V 思路很一致:
Agent 可以拥有很强的 reasoning。. From 1point 3acres bbs
但高 impact authority 的关键边界最好不要全部依赖模型临场判断。.google и
⸻
还有一个更有意思的 case。
假设一个 Fraud Agent 推荐:. .и
BLOCK TRANSACTION
它给 Human Fraud Analyst 的 summary 是:
High-risk transaction New device Foreign IP Unusual transaction amount
Human 点击:
BLOCK. From 1point 3acres bbs
但原始 evidence 还有:
Customer traveling: Confirmed Device: Registered 2 days ago Transaction: Hotel deposit matching itinerary
这些 facts 全部存在。
. ΧAgent 只是认为前三条更 relevant。. From 1point 3acres bbs
如果 Human 永远只看到模型的 relevance ranking,那么:
Human review
可能逐渐变成:
Human confirmation of Agent framing
这和真正独立的 review 有很大区别。
⸻. From 1point 3acres bbs
所以这里可以定义一个很有用的概念:-baidu 1point3acres
Review Independence。. check 1point3acres for more.
Human Review 的独立性不是:
A human clicked the button.
而要看:
Did the human have access to decision-changing evidence? Could the reviewer inspect the underlying sources? Were contradictory facts surfaced? Was the review package created independently from the recommendation? Were mandatory evidence categories preserved?
⸻
如果把它做成 Deployment Lab,我会先给用户一个 approval screen:
SUPPLIER REVIEW Recommendation: APPROVE Security: PASS Finance: PASS Legal: REVIEWED Overall risk: ACCEPTABLE
然后问:
Would you approve?
很多人可能会。 ..
下一步让用户点击:
SHOW SOURCE RECORDS
然后突然出现:
LEGAL REVIEW PASS WITH CONDITIONS
以及:
DATA RESIDENCY EXCEPTION STATUS: PENDING
再问:
Does your decision change?
如果变了,就说明:
被省略的信息是 material。. Waral dи,
⸻. Χ
第二个 case 可以给两个 summary。
Summary A:
Security review passed. No critical vulnerabilities.
Summary B:
No critical vulnerabilities. Two high-severity findings remain under compensating controls.
两句话都 factually correct。
然后问:. From 1point 3acres bbs
Which one is sufficient for approval?
用户会开始理解:
truthful
和:
decision-complete
之间的区别。
⸻
第三个 case 我会做 Recommendation / Review Coupling。
告诉用户:
Agent A: Recommendation = APPROVE Agent A: also generated the review summary.
然后提供另一份:
Independent Review Assembler. 1point 3acres
生成的 evidence package。
两者对比:
第一份:
3 supporting points 1 minor concern. 1point 3acres
第二份:
3 supporting points 3 unresolved conditions 1 execution blocker
原始 source 一模一样。
差别只发生在:
selection + compression
我觉得这个 reveal 会很有意思。
⸻
最终用户需要建立一个:
HUMAN REVIEW CONTRACT
至少包括:
Decision Reviewer Required Evidence Mandatory Risk Fields Supporting Evidence Contradictory Evidence Unresolved Conditions Missing Evidence Claim-to-Source Links Summary Generator Recommendation Generator Independence Requirement Material Omission Test Escalation Rule
然后 approval gate 不再只检查:
Human approved?
而是:
HUMAN REVIEW GATE Authorized reviewer? ✓ Required evidence shown? ✓ Contradictions surfaced? ✓ Material conditions visible? ✓ Source traceability available? ✓
最后才:
. 1point 3 acresAPPROVAL VALID
⸻
我觉得 Lab 19 最值得留下的一句话是:
Human authority is only as independent as the evidence surface the human is allowed to see.
或者更直接一点:
A human cannot independently review evidence that the Agent chose not to show.
Human-in-the-loop 当然仍然非常重要。.--
问题只是不能把:
human clicked approve
直接等同于:. 1point 3 acres
independent human judgment
尤其当 Agent 同时负责:
reasoning recommendation evidence selection summary generation
的时候。
这时候我们要审计的不只是最终是谁点击了按钮。 ..
还要问:
是谁决定了按钮前面出现什么?.--
所以我会把 Lab 19 叫:
The Human Approved the Summary
. From 1point 3acres bbs
接在 Lab 18 后面:
Lab 18 Agent-generated inference can become evidence. . ----
↓
Lab 19 Agent-selected evidence can shape human authority.
随着企业开始大量使用 Agent 去准备 executive review、risk review、approval package、case summary 和 investigation brief,这个问题会越来越现实。.
因为以后很多时候,Human 确实还在 loop 里。
只是他看到的那个世界,可能已经先被 Agent 编辑过一遍了。
. Χ
目前我们已经从:
Prompt
↓
. .иWorkflow
↓
Evidence. From 1point 3acres bbs
↓
Evaluation
↓
Production
↓
Authority
↓
Memory
↓. Waral dи,
Multi-Agent
↓
Human Decision
从人出发,回到了人,这是最后一个core lab。
希望deploytovalue.com能给用户最终问题和解答:
Can you now explain what your Agent can do, what it may believe, what it may decide, what it may delegate, what it may execute, and what evidence justifies each boundary?
.1point3acres
以后我们当然还会想到很多问题,比如 Agent retirement、rollback semantics、shadow deployment、cost governance、model migration、policy change、simulation、red teaming……
但这些可以进入下一层。
. From 1point 3acres bbs
deploytovalue.com |