Interaction policy layer
A reusable set of product rules defining what an AI may present, decide, execute, defer, expose as uncertain, require confirmation for, make reversible and escalate in a given interaction.
An interaction policy layer is the reusable product contract between an AI system's technical capability and the interaction a person is allowed to experience. It answers a different question from whether an agent can call a tool or whether a screen uses the correct component: given that the system can do something, what may it present, decide, execute, defer, expose as uncertain, require confirmation for, make reversible and escalate?
It matters because agentic products increasingly turn generated judgment into actions. Without an explicit interaction policy, authorization rules, risk policy, UX guidance and workflow logic can reach the user as contradictory signals. A polished interface may offer an action the organization would not actually want the AI to take.
Use the layer as a shared vocabulary across product, design, engineering, risk and accessibility. Attach the relevant rules to capabilities and workflows, then make them observable in UI states, tests and runtime controls. It complements boundary design, guardrails and human in the loop; it does not replace identity, authorization or risk controls.
Read more in Design systems need an interaction policy layer for AI.
Related terms
Boundary design
Designing where an AI system's authority starts and stops: which actions it may take, with what data and permissions, and where it must hand back to a person or recover.
Guardrails
Controls placed around an AI system — input and output checks, permission limits, review steps and escalation rules — that keep its behaviour within acceptable bounds.
Human in the loop
A design where a person reviews, approves or corrects an AI system's work at defined points. In practice it can mean a person with real judgment, or a person who has become the loop.