Humans miss agent permission threats

Approve/deny UX is a safety surface — fatigue and familiar wrappers hide exfiltration.

Analyses of approve/deny games for coding agents keep finding the same pattern: people catch obvious destruction and miss quieter scope violations and exfiltration, especially when danger is wrapped in familiar tooling (npm scripts, helpers).

Treat human-in-the-loop as part of the system design — not a checkbox. Reduce decision fatigue, make intent visible, and assume reviewers will miss a third of the threats under load.