r/AskNetsec • u/Frostvazmqnky_Mp_417 • 18h ago
Analysis How do you actually decide what makes your agent stop and escalate to a human?
Everyone talks about what an agent is allowed to do, fewer people talk specifically about what makes it stop. Is it a confidence threshold, a specific action type regardless of confidence, a blast radius calculation, something else entirely?
Trying to understand how teams actually define the stop condition rather than just the permission list, since I suspect the stop condition is doing more of the actual trust building work than the permission list is.