Every vendor demo ends the same way. The agent plans, executes, recovers from its own mistake, finishes the job — and the presenter delivers the closing line with practiced awe: it did all of that by itself. Every enterprise deal for that same product dies the same way, months later, in a different room, when the CISO asks the question the demo was built to avoid. Who approved that?
The silence that follows is the whole market, compressed. Enterprises do not buy autonomy. They buy autonomy with accountable gates — and the named human at the gate is the feature, not the compromise that got the deal signed.
Definition by negation helps here. Autonomy theater is a system whose impressiveness depends on nobody asking who is responsible. Deployed autonomy is a system that can answer the question in writing. The distance between the two is not model quality — the same model can power either. The distance is infrastructure.
The management layer
The logic is already sitting in the market’s favorite essay, though it rarely gets read this far. a16z’s Joe Schmidt argues that software is becoming the worker rather than the worker’s tool, and that digital labor therefore needs what human labor has always needed: onboarding, supervision, and someone accountable for its output. Follow the argument one step past where most people stop quoting it. Every worker an enterprise employs reports to someone. A named manager approves the consequential actions, answers for the output, and is findable when something goes wrong. If software is the worker, someone has to be its manager — and a named approver is what a management layer for digital labor concretely looks like.
Sierra arrived at the same place from the engineering side. Its “Agent Development Life Cycle” is a quiet admission that non-deterministic systems cannot ship on the old SDLC: regression suites built from annotated real conversations, releases gated on them, an audit surface underneath — because an agent that behaved well yesterday is not evidence about tomorrow. Nowhere does Sierra present this as a limitation of its agents. The control surface is how the agents get to run at all.
Under both arguments sits a concrete design pattern, and it separates deployable systems from demos. Natural-language intent goes in. What comes out the other side is a typed, policy-checked action: a specific operation against a specific system, evaluated against what this actor is permitted to do, logged with who approved it. The agent never holds raw access to client systems. The alternative — a language model holding production credentials and good intentions — is autonomy theater, and it is impressive right up until the first incident review.
This is also why “human in the loop” has become a nearly useless phrase. A human somewhere in the loop is a diffusion of responsibility; a named human at a defined gate is an assignment of it. Enterprises can tell the difference, because their auditors can.
Inside a CMS-regulated health plan we operate in, compliance did not force the gate on us. The gate is why compliance said yes. Every privileged action stops at a named person, and the record shows who and when. Once we could demonstrate that, the conversation changed — from whether AI belonged in the workflow at all to how much of the workflow it should carry.
The gate that earns its own expansion
The engineering objection deserves a straight answer: doesn’t a human gate defeat the point? If a person reviews everything, you have built an expensive suggestion box. But the gate is not on everything. It is on privileged actions — the small fraction of the work with consequences that are hard to reverse. The agent drafts, retrieves, reconciles, and prepares at machine speed; the human approves the state changes that matter. And the ratio is not fixed. Every gated approval generates evidence about where the system is trustworthy, and that evidence is precisely what lets the gates move outward over time. Ungated autonomy can never earn that expansion, because it never produces the record.
The control plane is not a tax on the AI system. It is the reason the AI system gets deployed instead of piloted forever. Vendors still selling it did it all by itself are optimizing for the demo. The room that decides contains a CISO, a compliance officer, and one question.
LockedIn Labs FDE is built as that answer: a platform where every privileged action resolves to a typed, policy-checked operation and stops at a named human — accountability shipped as infrastructure.
LockedIn Labs FDE is the platform forward-deployed engineers carry into the enterprise — the operating reality held as a governed asset, workflows and agents as reviewable definitions, and every privileged action stopped at a named human.
