Big Tech Accountability
Human-in-the-Loop

HITL for Learning Designers Building Courses

By Michael Polzin, Regenerative Architect. Published 2026-07-01.

Most course structures inherit their shape from a manufacturing metaphor: input the learner, run them through the sequence, output a completion. Human-in-the-loop is a different shape. It puts the learner's veto, and the learner's repair, inside the structure of the course itself.

This is for instructional designers baking that discipline in at the blueprint stage. Four moves do most of the work: checkpoints, opt-ins, repair pathways, tool-use logs.

The frame this design work sits inside

The IamHITL front is grounded in active inference (Class E, standard formulation in Parr, Pezzulo, and Friston, 2022): a mind predicts what happens next, notices where its prediction and the world disagree, and quietly updates its map. A course, seen this way, is a scaffolded environment where a learner's existing model meets structured surprise and gets a chance to update on their own terms. If the learner is the generative model, then design choices that remove the learner's ability to steer, pause, or refuse are not neutral. They break the loop.

1. Checkpoints, not gates

A gate asks: did you get it right? A checkpoint asks: what did you predict, what happened, and what do you want to do next? A gate outsources the update decision to the course. A checkpoint keeps it inside the learner.

In a blueprint this shows up as three fields at every checkpoint, not one. Before the segment: what do you expect. During: what did you notice. After: what, if anything, do you want to change about how you go into the next segment. These fields do not need to be graded, only legible to the learner later. Whether specific checkpoint cadences hold up across cohort sizes is (Class U) not yet demonstrated in our data; the falsifier will go up with the publication.

2. Opt-ins that are actually opt-ins

An opt-in the learner cannot refuse without leaving the course is not an opt-in. It is a fee dressed up as a choice. Real opt-ins are structural: an alternative path, a private-mode option, a "skip this activity, keep the credit" lane, a way to substitute one exemplar for another.

The working test: for every activity that touches identity, disclosure, or risk, name one alternative that keeps the learner in the course without an emotional or reputational tax. If you cannot, the activity is not opt-in. Rewrite it, or move it off the required track. This is trauma-informed, non-clinical design: no clinical claim, no treatment, just a refusal to add more harm through the shape of the course.

3. Repair pathways, on the map

Most courses handle a failed attempt with a retry button and a lower grade. That handles the transcript, not the learner. A repair pathway treats a failed prediction as the invitation to update the model, and it gives the learner a named place to do that work.

Every unit needs at least one repair pathway next to the main path: a worked example that walks the mistake, a shorter re-attempt with different surface features, a conversation prompt for facilitator or peer, a "let it sit and come back" option the course honors instead of punishes. A learner meeting a wall in Unit 3 should have a visible, low-cost route through it, and that route should be part of the course rather than an exception to it (Class C, this is how the intake webhook and repair-loop logs on our own instance are wired).

4. Tool-use logs the learner owns

If the course allows or expects tools (language models, spellcheckers, search, translation, or a peer), the course should keep a tool-use log, and the learner should own it. Own it means: they can see every entry, add a note, mark an entry private, and export the whole log at the end.

The log is not surveillance, it is memory. It lets the learner notice their own pattern and update it, or not. It lets a facilitator see where structured help lands and where it is missed. It lets the course itself be inspected later, which is the same posture the wider site takes toward its own claims. See Receipts, Not Vibes for why the record matters more than the vibe. A learner who cannot delete an entry from their own log has not been given a log; they have been given a monitor. Design the export and the delete into the schema from day one.

What this rules out, and a short close

Framed this way, several familiar course-design patterns fail the check: a one-shot high-stakes summative with no repair pathway, a mandatory tool with no substitute, a checkpoint that only asks whether the learner got it right, a tool-use log the learner cannot see or export. Human-in-the-loop, in a course, is not a slogan on the syllabus. It is four structural choices in the blueprint. Do those four, and the rest of the course starts pulling in the same direction.

Read next

  1. Human-in-the-Loop, What It Actually Means When a Learner Is in the Room. The cornerstone piece this design guide sits on top of.
  2. Receipts, Not Vibes. Why a course that leaves a legible record is doing something a vibe-based course cannot.
  3. The UNI workshop. The paid deep-dive where instructional designers, facilitators, and team leads build this discipline with us, in the open.