03 / Autonomous systems
Designing the moment when a machine asks a person for help
Interface patterns for system state, uncertainty, alerts, interventions, and the record left after a human takes control.
Design the handoff as a workflow
An alert is only the beginning of a human handoff. The operator needs to recognise the affected unit, understand the current state, see why autonomy stopped, assess nearby risk, and choose a safe action. The interface should organise that sequence instead of presenting a wall of telemetry.
Priority should reflect consequence and time, not the volume of available data. A clear operating view separates immediate decisions from supporting evidence and background diagnostics.
Show uncertainty without creating noise
Autonomous systems rarely have perfect information. Confidence, stale sensor data, degraded components, and ambiguous conditions should be visible in language an operator can use. Raw model scores are rarely enough on their own.
The system should explain what changed, which assumptions no longer hold, and what information would reduce uncertainty. This helps the operator decide whether to continue, pause, reroute, or inspect.
Leave a record that improves the system
Every intervention should capture the state, evidence, operator action, and outcome. That record supports incident review, training, product decisions, and later evaluation of the autonomous behaviour.
Recording should happen as part of the operating workflow. If it depends on a separate report at the end of a difficult event, important context will disappear.