Skopa

AI

AI in the enterprise, without losing control: Human-in-the-Loop and audit log

Emanuel Flury·30 April 2026·7 min read

The real question about AI in the enterprise is not “can it do this?” but “who is accountable for it?”. Two building blocks that make control and automation compatible.

The widespread fear of AI in the enterprise is rarely a fear of poor performance. It is a fear of losing control: that a system will, on its own initiative, send something to a customer, trigger a payment or alter a data record without anyone having approved it — and that afterwards no one can retrace why. In regulated Swiss contexts, under the revised FADP/revDSG and the expectations of audit and the board, this concern is not merely justified; it is the decisive question of all.

The good news: control and automation are not a contradiction. They are simply often played off against each other because the wrong idea of automation prevails — that of a system which replaces the human. The viable idea is a different one: a system that takes over the manual work and leaves the decision where responsibility lies. Two building blocks make this possible.

Human-in-the-Loop: the gate is in the code

Human-in-the-Loop means that the automated workflow runs unsupervised until it reaches a sensitive step. There it stops and requests an approval. Nothing that has an external effect or does anything irreversible happens without a human confirming it. The customer-facing result is at first “pending” — it waits until a person approves it.

The decisive point is where this gate sits. An approval step written into a work instruction is a request. An approval step anchored in the code is a guarantee. The system technically cannot execute the sensitive step before the approval is in place. This shifts safety from the discipline of individuals to the architecture of the system — and that is exactly where it belongs.

What matters here is placing the gate wisely. A system that asks for approval at every step has automated nothing — it has merely renamed the manual work. The art lies in the distinction: what is reversible and low-risk runs through; what has an external effect, moves money or alters data waits for a human. This preserves the time saved without losing control.

«An approval step in a work instruction is a request. The same step in the code is a guarantee.»

The audit log: traceable, not just fast

The second building block answers the question that is eventually asked after every automation: what actually happened — and why? An audit log is the complete, immutable record of every action the system performs. Every run, every approval, every exception is captured with a timestamp: what happened, when, on what data basis, and who approved it.

This sounds technical, but above all it is a governance question. An audit log turns an automated process from a black box into an auditable system. It answers the questions of the audit before they are asked. It makes visible whether a result was approved by a human or ran through automatically. And in the end it also protects the people who approve — because their decision is documented and defensible, instead of seeping away into an email thread.

Why the two belong together

The two building blocks complement each other. The Human-in-the-Loop gate ensures that the right decision is made by a human at the right moment. The audit log ensures that this decision — and everything automated around it — remains traceable in hindsight. One controls the present, the other secures the past. Only together do they form a system for which one can take responsibility.

These principles are easy to claim. That is why we applied them to ourselves first: the platform on which our clients see their systems, we built ourselves — with the audit log and Human-in-the-Loop as the foundation, not as an add-on feature. Operation and storage are in Switzerland, in the Zürich region, compliant with the revised Federal Act on Data Protection.

Where the human stays — and where not

A common concern is that Human-in-the-Loop is just a nicer word for “everything stays manual”. The opposite is the aim. The goal is not to build the human in everywhere, but to deploy them precisely where their judgement makes a difference — and to free them from repetition everywhere else. A well-built system does not bring a human a hundred approvals a day, but the few where a decision truly matters.

It is precisely for this reason that classifying what is reversible and what is not is not a technical question but a business one. It belongs at the beginning of every project, not at its end. We clarify it within our methodology — Discover, Build, Test, Rollout, Operate — with a gate at every sensitive step, before the first line of automation goes live. Control is thus not bolted on afterwards, but is part of the design.

The real question

Anyone introducing AI in the enterprise should therefore not first ask “What can the system do?” but “Where does it stop, and what does it record?”. The capability of AI is rarely the bottleneck today. The bottleneck is trust — and trust arises not from promises, but from an architecture in which control is not optional but built in.

Understood in this way, AI takes work off your hands without taking control away from you. It handles the repetition, it stops at the sensitive points, and it logs completely what it has done. The result is not a system you have to trust — but one you can verify. That is the difference.

In the end, then, the choice is not between progress and safety. Anyone who believes they must decide between the speed of AI and control over their company has framed the alternative wrongly. Built correctly, control is not a brake but the condition under which one can afford speed at all. A gate that stops at the right moment, and a log that captures everything, are not what stands in the way of automation — they are what makes it defensible in the enterprise.

AIGovernanceHuman-in-the-LoopAudit logrevised FADP/revDSG

written by

Emanuel Flury
Emanuel Flury

Founder of Skopa. Nearly ten years of process automation in Fortune-500 environments, today for Swiss SMEs.

intro call

Have a process we should talk about?

An intro call is non-binding and concrete: we look at a real workflow and tell you honestly whether and where automation pays off.