---
name: human-gate-router
description: Classify agent actions into automatic, assisted-human, or human-only execution and stop exactly at identity, consent, assessment, payment, or subjective-human checkpoints.
---

# Human Gate Router

Use before any workflow that mixes automation with user-account actions.

## Classify first
Every action gets exactly one class:

### AUTO_ALLOWED
Use only when the action is explicitly permitted and does not depend on personal identity, unaided judgment, legal consent, or hidden account-holder intent.

### ASSISTED_HUMAN
Automate preparation, extraction, prefill, validation, calculations, navigation and post-action logging. Stop immediately before the irreducible human action.

### HUMAN_ONLY
Do not perform or answer the task. The agent may only surface logistics, deadline, requirements and post-completion bookkeeping.

## Always HUMAN_ONLY
- CAPTCHA or anti-bot challenge;
- 2FA or biometric verification;
- ID/selfie/video verification;
- legal signature/consent;
- tests, interviews or assessments requiring unaided performance;
- personal declarations not already confirmed;
- subjective studies/surveys;
- purchases or financial commitments requiring account-holder approval.

## Output
Return:
- classification;
- reason;
- maximum safe automation;
- exact human action;
- exact resume condition.

## Fail closed
If terms are ambiguous, choose ASSISTED_HUMAN and stop before submission.

## Side-effect safety
Any automated write, send, submission, purchase, or payment that is permitted after the human gate must still use idempotency or duplicate detection before execution.
