Agentic UX
Definition
Design for AI agents that take multi-step actions for a user, focused on showing the plan, asking approval before consequential steps, and keeping control.
Agentic UX is the design of products where an AI does not just answer, it acts: searching, filling forms, sending messages, booking, buying or changing files over several steps. The core design problem shifts from "is the answer good?" to "what is it about to do, and can I stop it?" Approval steps, sometimes called confirmation gates or checkpoints, are the central pattern: the agent pauses before actions that are costly, public or hard to reverse.
Why it matters
When an assistant gives a bad answer, the user can ignore it. When an agent books the wrong flight or emails the wrong person, the mistake already happened. Apple's generative AI guidelines are direct about this: "Avoid automating destructive actions, like deleting photos, and actions that are hard to undo, like making a purchase on a person's behalf. Generally, ask for confirmation before performing a significant action on someone's behalf."
Users also want efficiency without giving up control. In NN/g's study of an agent that ordered food and booked travel, the authors summarize: "Users want efficiency, but not at the cost of control." Participants needed to see fees, final prices and details like baggage allowances before committing.
How to apply it
Do:
- Show the plan before acting on anything consequential. Anthropic's guidance on building agents recommends "explicitly showing the agent's planning steps."
- Tier actions by risk. Let a travel agent search and compare freely, but stop for approval before paying, sending, deleting or sharing data.
- Make the approval screen concrete: what will happen, to whom, for how much, and whether it can be undone. "Book this flight? $412, non-refundable, charged to Visa ending 4421" is an approval. "Continue?" is not.
- Let people edit at the checkpoint, not just accept or cancel. Changing one detail should not restart the whole task.
- Keep a visible, interruptible activity log while the agent works, with a Stop control that actually halts it.
- Pause when uncertain. Anthropic notes agents "can then pause for human feedback at checkpoints or when encountering blockers." The HAX guidelines (G10) ask systems to "Scope services when in doubt."
Don't:
- Ask for approval on every trivial step. Constant prompts train people to click Approve without reading.
- Bury consequences in a collapsed log the user will never open.
- Treat a one-time permission as standing permission for riskier actions later in the task.
Common mistakes
- Confirmation fatigue. Gates on low-risk steps make the high-risk gate easy to miss. Fewer, better checkpoints work better.
- Vague summaries. Approving "Update CRM records" without seeing which records invites automation bias.
- No recovery path. If an action cannot be undone, say so before it runs. If it can, offer undo right after.
- Over-collecting personal data. NN/g recommends explaining what data the agent accesses and showing only the minimum needed at each step.
- Silent long runs. An agent that works for minutes with no visible progress looks broken, or worse, trustworthy when it should be checked.