Pause the model,
keep the browser.
A person can take over the same live session, complete a sensitive step, attach task files, and return control to the existing thread.
Handoff sequence
- 1Agent requests help
The tool gate closes immediately.
- 2Earlier input drains
No human action overlaps an in-flight agent command.
- 3Human control is issued
The person uses live visual preview and bounded input.
- 4Resume explicitly
A fresh agent capability opens tools and starts the next turn.
Payment stays agent-owned when authorized
A valid pre-authorized payment policy requires the agent to complete purchase and payment end to end. Payment alone does not trigger takeover. Handoff begins only when the policy is missing or exceeded, the merchant or total changes, the payment instrument is unavailable, a CAPTCHA or strong customer authentication requires user presence, or the mutation outcome is unknown.
Task files
During takeover a person may add up to five supported text files with a 200 KB aggregate UTF-8 limit. Adding a file does not send it to the page or model until explicit resume. Browser file selection uses a task artifact ID, exact page origin, and bounded selector.