Layer 8: Human Oversight
The slowest and highest layer: human operators who set intent, approve exceptions, and make the judgments no automated layer should make alone.
People set the intent
Automation executes plans; humans decide what the plans are for. Operators choose the scenario, set the goals of a campaign, and define the limits inside which automation is free to act. The control stack is an instrument that carries out human intent faithfully and predictably, not a substitute for it.
Where humans belong in the loop
- Approving or vetoing off-normal responses that carry hardware risk
- Deciding whether to continue, pause, or abandon a campaign
- Adjudicating conflicting recommendations from lower layers
- Interpreting novel behavior no model has seen before
- Authorizing changes to limits and safety envelopes
Why humans cannot be in the fast loop
Human reaction time is hundreds of milliseconds at best - far too slow for vertical stabilization or disruption reflexes. So oversight operates on the scale of seconds and above. During a discharge, humans supervise; between discharges, they analyze, decide, and re-tune. The stack is built so that the fast, unsupervisable decisions are exactly the ones made safe by design in the lower layers.
Presenting the right picture
Effective oversight depends on the interface. Operators need a compressed, honest view: the plasma state, the plan, the margins to each limit, what the predictive layer expects, and what the stack has done autonomously. Overwhelming operators with raw data is as dangerous as hiding it. The design goal is calibrated situational awareness.
Accountability
Every autonomous action is logged with its trigger and rationale so that humans can reconstruct why the stack behaved as it did. Automation earns trust by being auditable. The highest layer is not a rubber stamp on the machine's choices; it is the point where responsibility rests.