“Keep a human in the loop” sounds like the safe compromise between manual work and autonomous machines. The agent acts; the person checks. No consequential decision escapes human oversight.
At small scale, this can work. At company scale, the loop consumes the person. Every approval has a reading cost. Every notification breaks concentration. Every ambiguous request forces the owner to reconstruct context the system already had. As machine throughput increases, the human either becomes the bottleneck or learns to approve without thinking. Both outcomes defeat the purpose.
Restless is built around a different shape: machine freedom inside, human authority at the edge. The distinction is not a slogan about autonomy. It is an architecture for preserving the scarce resource that human oversight actually depends on—attention.
Approval volume is not control
A system can ask permission for every tool call and still leave the owner poorly informed. The person sees a stream of low-level actions: read a file, run a command, fetch a page, edit a draft. Each action is individually legible, but the consequence of the sequence is not. The owner approves motion without understanding direction.
Frequent approvals also train a behaviour. When ninety-nine prompts are routine, the hundredth inherits the same reflex. Security researchers recognise this as warning fatigue; managers recognise it as rubber-stamping. The interface can honestly record human approval while the human contribution has become ceremonial.
The relevant measure is not how often a person appears in the workflow. It is whether the system brings them the decisions that require their judgement with enough evidence to decide well. A hundred acknowledgements can contain less human control than one carefully prepared return.
Attention is part of the systems budget
Engineering budgets usually track compute, tokens, latency, and money. Owner attention is left implicit because it is difficult to meter. Yet attention is often the hardest capacity limit. A founder can buy more inference. They cannot add a second uninterrupted morning to the day.
Attention has at least three costs. There is interruption cost: stopping current work and loading a new context. There is reconstruction cost: discovering what happened before the question arrived. And there is judgement cost: evaluating alternatives under uncertainty. Poor agent systems transfer all three to the owner while reporting that they saved execution time.
A useful attention envelope therefore records more than a count of messages. It asks whether the interruption was necessary, whether the decision arrived prepared, whether similar questions could be batched, and whether the company learned enough to avoid asking again.
Derive attention from unresolved facts
Many systems assign urgency by asking a model to score a message. That can help with presentation, but it is a weak foundation for authority. A confident model may call its own preferred action low-risk. A cautious model may label every ambiguity important. The attention queue becomes another expression of model temperament.
Restless begins with source-owned facts. Is a required credential missing? Did a deterministic gate reject the artifact? Does the next action exceed an existing capability or budget? Is an external effect in an unknown state? Did the owner explicitly reserve this decision? Did evidence reveal a material trade-off that no accepted policy resolves?
Those facts do not eliminate judgement. They decide whether judgement is needed and where the answer must be written back. An Authority request resolves in the Authority Plane. An owner handoff resolves against its Work. The cockpit projects both through one attention surface without becoming a second owner of their state.
- Routine compliant work continues without asking for applause.
- Missing capability produces a bounded request, not a vague plea for help.
- Unknown external outcomes trigger reconciliation before retry.
- Strategic ambiguity returns with alternatives, evidence, and the cost of waiting.
A decision should arrive prepared
Delegation fails when the owner receives the hard part in raw form. “Which option do you prefer?” is not a useful return if the system could have compared the options, tested assumptions, and identified the consequence of each. The machine has saved its own effort by transferring uncertainty upward.
A prepared decision packet should contain the proposed action, strongest supporting evidence, credible alternative, material uncertainty, authority required, reversibility, and immediate consequence of delay. It should link to the native artifact or external system where the decision can be judged. Supporting logs remain available without becoming the default surface.
Preparation changes the owner's role. They are not supervising a process minute by minute. They are exercising taste, responsibility, relationship knowledge, and risk appetite at the point where those human capacities alter the outcome.
Human authority is narrower than human participation
A person may participate in a task without exercising authority. They can answer a factual question, supply taste, or demonstrate a process. Conversely, an automated system may prepare an action perfectly but still lack the authority to perform it. Mixing these concepts produces either unnecessary interruption or unsafe autonomy.
Restless treats authority as a separate boundary. Models can explore, edit, test, browse, and prepare within their granted environment. Identity checks, capability expansion, budget enforcement, consequential effects, and authoritative receipts remain deterministic. The model may explain the request; it cannot approve its own expansion.
This arrangement is intentionally asymmetric. It gives the machine broad discretion over reversible work and narrow discretion over consequence. The owner does not need to approve the path through every file edit. They retain the decision that changes the company's commitments or the external world.
Quiet systems still need rescue
Reducing notifications cannot mean hiding the company. The owner needs a way to inspect active responsibility, freeze consequences, stop an actor, revoke a capability, attach to the runtime, or restore internal state. Rescue controls matter precisely because they are not the normal workflow.
The primary surface should remain calm: current outcomes, genuine decisions, material risk, and next actions. Deeper views can reveal roles, prompts, spend, messages, permissions, and logs when a problem requires investigation. Progressive disclosure is not aesthetic minimalism. It protects the owner's ability to see the few things that currently matter.
Silence also needs observability. If the system is doing nothing because it is healthy, the interface should say so differently from doing nothing because a wake was lost. Attention reduction must not make operational failure indistinguishable from peace.
There are tasks that deserve continuous human presence
Not every workflow should move the human to the edge. Negotiation, therapy, hiring judgement, sensitive leadership, and exploratory creative work can depend on continuous relationship and interpretation. The human contribution is not a final gate added to otherwise mechanical production; it is part of the work's substance.
The mistake is turning “human at the edge” into a universal automation doctrine. Restless should classify where judgement lives. If the human interaction generates the value, the system can prepare context, capture commitments, and reduce administration while keeping the person inside the activity.
The attention argument is therefore about removing avoidable coordination, not minimising human presence as an end in itself. Good automation makes human attention more intentional. It does not treat attention as waste.
Alignment needs an awake human
Many discussions of alignment focus on whether the system follows instructions. In a company, instructions are incomplete and sometimes contradictory. The deeper question is whether unresolved consequence reaches someone capable of judging it before that person's attention has been consumed by noise.
A human technically present in every loop but cognitively absent from most decisions is not a safety architecture. A system that runs routine work quietly, preserves evidence, and stops at a clear authority boundary may be more autonomous and more controllable at the same time.
The purpose of Restless is not to remove the owner. It is to stop spending the owner on work machines can already do, so the owner remains available for the decisions that still make the company theirs.