L4.01.3user-adjustable automation leveldesignresearch

The level must be adjustable by the user

Aliases: adaptable automation · user-set LOA · manual level control

What it is

If the continuum can only be chosen by the designer and locked at runtime, the user has no legitimate retreat when trust drops, when they need to practise, or when the task gets harder. User-adjustable automation level requires the level to be a state the operator can move, not a factory setting. Adaptive automation is the system moving the level with load; this entry is the person moving it on purpose.

A switch that only offers “hand it all over” or “do it all myself” is not adjusting a level. It is swapping products.

Why it happens

Trust, skill and situational load all move. On the same pipeline, a morning shift may fit an advisory level; a tired night shift may want to step up to execution to save effort; the next key client may demand a drop back to manual. If the level cannot be moved, people take bypasses: they turn the feature off, move the work to another tool, or leave automation on and stop watching. Bypasses let designers believe the level was accepted.

Adjustability presupposes that the level is visible and that the permission gap between levels is intelligible. A slider that only changes copy, not authority, is fake. A slider that changes authority without changing the information in front of the person leaves them on an execution level they just chose, suddenly missing the intermediate steps.

Studying it

Contrast adaptable automation (the person picks the level) with adaptive automation (the system moves it with load). Independent variables: whether a control exists, granularity (two steps versus four stages separately), whether a change takes effect immediately. Dependent variables: distribution of chosen levels, fault detection, felt control, whether “nominally on, actually bypassed” appears.

Training studies that let people step down under low load in order to practise speak to the long-term value of adjustability; short-term scores need not improve.

Where it stops holding

Safety-critical procedures that lock the level (some sign-out flows) cannot be left to individual upshifts. Down but not up is a common asymmetric constraint. System-driven adaptive changes are a different design; they can coexist with human adjustment, but a conflict rule — who overrides whom — must be stated. Duty follows level, so the act of changing level itself must be logged.

Applying it

  • Offer at least three rungs — advise, execute after approval, execute then inform — each with a real permission gap, not a reskin.
  • A change takes effect immediately and leaves the current rung visible. Do not bury the control in a one-time setup wizard.
  • Stepping up to execution needs an extra confirm; stepping down must be possible at any time, in one step.
  • Check: mid-task, ask “make it advise only, do not send.” If that is impossible, or requires quitting and restarting, the level is not user-adjustable.

Related

  • Same group: L4.01.1 From suggestion to full autonomy is a continuum · L4.01.2 The level determines who is accountable
  • Nearby: L4.04 Takeover and Handoff Design · L4.09 Skill Degradation · L4.06 Permission Boundaries of Agents
  • Search terms: adaptable automation · user-adjustable LOA · levels of automation

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/L4.01.3