Risk & Accountability
What happens when things don't go as planned
Decision error
As with any professional decision:
- responsibility lies with the identified human who made the decision
- within their qualifications, authorizations, and legal obligations
HumanLayer:
- never decides
- never modifies the decision
- always keeps the link between the decision and the Sentinel’s identity (the client sees a pseudonymous reference)
👉 HumanLayer provides the evidence, not the decision.
Abuse protection
HumanLayer implements several safeguards:
- strict scope of authorized decisions
- logging of sensitive actions (logins, decisions, API keys, exports)
- possibility of immediate suspension
Client organizations can:
- report a Sentinel to HumanLayer, which can suspend them
- require a second opinion
- export their signed decisions and ask HumanLayer for a targeted audit
👉 Abuse is more visible, not less.
AI context
HumanLayer:
- records the context as received (summary capped at 5,000 characters, context_json at 50 KB)
- timestamps the information
- makes it read-only once submitted
The Sentinel:
- decides based on that context
- can reject with a justification (e.g., insufficient context) or escalate to another Sentinel
👉 In case of incident, it's always possible to determine:
- what the AI provided
- what the human saw
- what the decision was based on
Prohibited uses
No.
HumanLayer explicitly rejects:
- illegal decisions
- uses intended to circumvent regulations
- requests outside the defined scope
The API rejects requests outside your plan or outside supported domains; unlawful uses are excluded by contract, and HumanLayer can suspend an API key.
Responsibility allocation
- The decision: the Sentinel
- The usage framework: the client organization
- Orchestration and traceability: HumanLayer
This clear separation is essential and contractual.
HumanLayer is not a decision-making actor.
Its liability is limited to:
- proper service execution
- traceability
- availability per SLA
👉 It is an infrastructure provider, not a Sentinel.
Insurance and protection
Depending on the decision level:
- Sentinels operate within their usual professional framework
- some decisions may require specific insurance
- additional coverage can be offered as an enterprise option
The exact terms are contractual and transparent.
Blocking an action
Yes, if your agent waits for the decision.
HumanLayer never approves anything automatically: until a Sentinel has rendered an approved decision, justified and signed, your agent should not act. If in doubt, request a second opinion (second_opinion_of). Risk thresholds, automatic rejection rules, mandatory escalations and multi-signature validations are not available.
👉 No approval without a signed human decision.
In summary:
HumanLayer doesn't eliminate risk.
It makes it visible, traceable, and attributable.
Questions about security?
Contact the team