Designing the pass-through in agentic computing
Designing the pass-through in agentic computing
How a restaurant analogy reveals what we need to know about designing for Human-Agentic Interaction
Photo by Sebastian Coman Photography on Unsplash
Those who work with me know I love a good analogy. Finding analogies is a great way to connect the everyday and domain-specific knowledge in the most generalised ways. And anyone who works with me recently knows I’ve been leaning a fair amount into kitchen analogies.
Have you ever observed that particular moment in a well-run restaurant when a plate appears at the window from the kitchen? That small window is what is known in restaurant architecture as ‘the pass-through’ or ‘the service hatch’. It’s nothing more than an aperture between the kitchen and the dining-floor. A server collects it and delivers it to a table with minimal ceremony. The diner experiences the result in a beautifully composed dish, correctly seasoned, arriving at the right temperature.
What they do not see is the whole brigade of cooks who butchered, reduced, blanched, and plated it across a twenth-to-forty-minute sequence of coordinated effort. The kitchen is loud, hot, and complex. The dining room is calm, curated, and simple.
Between them is this ‘pass-through’ window, and it’s a helpful analogy to think about how interfaces operate, especially in a world where increasingly more of the effort is obfuscated.
As UX practitioners and product designers, we are now designing for systems that operate on precisely this logic. In the new agentic operating model, AI increasingly does not just respond, it acts. It browses, writes, executes code, calls APIs, coordinates sub-agents, and returns with a result.
The user sees none of this. They just see the plate. And that’s what I think we are (whether we have named it this way or not) designing: pass-throughs. The user (and the designer) is increasibly the diner who judges the plate.
Photo by Ali Aksu on Unsplash
What agentic computing actually means
The term agent, as it applies to AI systems, describes a model that takes sequences of actions autonomously in pursuit of a goal, rather than simply producing a single response to a single prompt. This is a meaningful departure from the conversational paradigm that has shaped most AI product design to date.
Researchers at Anthropic describe agents as systems where “Claude will sometimes act as an orchestrator of multi-agent pipelines and sometimes as a subagent within those pipelines, and sometimes as both.” The model is very cybernetic, such that the orchestrator directs and the subagents act. Tools are invoked (from web search, code execution, file management, external APIs) and the whole apparatus operates across time, sometimes across minutes, sometimes longer, and the user is not present for any of it.
This is the kitchen. The user is in the dining room.
Photo by Louis Hansel on Unsplash
The architecture of the pass-through
In restaurants, and some fancy houses, the pass-through (also called “the pass”, the “service window”, or the “expediting station”) was a deliberate architectural decision, and was never just a gap in a wall. It was and still is a designed threshold whose purpose is to mediate between two incompatible environments: the productive disorder of the kitchen and the controlled experience of the dining room.
The pass-through performs several functions simultaneously. It acts as a quality checkpoint, the last point at which the kitchen can inspect a dish before it leaves their domain. It acts as a translation layer converting the language of the kitchen (ticket numbers, table covers, fire times) into the language of the floor (table numbers, guest preferences, pacing). And it acts as an information boundary deliberately concealing from the diner all the information that would overwhelm or disturb them if revealed.
A diner who could see directly into the kitchen during service would have an entirely different, and by some definitions a worse, experience. Not because the kitchen is doing anything wrong. Quite the opposite in fact, because the cognitive load of witnessing the full process would interfere with the experience the kitchen is trying to deliver.
This is precisely the challenge agentic UX now presents.
The three functions of the pass, applied to agentic design
1. Quality checkpoint
In a kitchen, the head chef stands at the pass and inspects every plate before it goes out. A smear on the rim is wiped. A garnish is repositioned. The dish is evaluated against the standard before it is handed over.
In agentic computing, this translates to what alignment researchers call human oversight — the principle that consequential outputs should be reviewable before they are acted upon. The Nielsen Norman Group has described this in the context of AI agents as the need for “confirmation points” and “human-in-the-loop checkpoints” that allow users to intercept an agent’s work before it becomes irreversible.
The design challenge here is substantial, because Agents move fast. Really fast. Their internal processes generate enormous quantities of intermediate outputs such as draft documents, sub-queries, tentative decisions , etc. that are not meaningful to a user and would not benefit from review. But their terminal outputs , i.e. the email that is sent, the file that is deleted, the purchase that is made etc are highly consequential. The UX practitioner’s task is to design a pass that catches the right plates.
This requires us to think carefully about what consequential means in context. A restaurant pass-through is staffed by someone who knows the difference between a mise-en-place error and a plating error, between something that can be corrected in thirty seconds and something that requires the dish to return to the kitchen. We need analogous judgement built into our interfaces — the capacity to distinguish between actions that warrant interruption and actions that do not.
2. Translation layer
The language of an agentic process is not the language of a user’s goal. An agent asked to “book me a flight to Edinburgh next Thursday” might navigate three websites, compare seventeen fare options, handle a CAPTCHA, parse a terms-and-conditions document, and encounter two dead ends before completing the task. None of this is what the user asked for. The user asked for a ticket, and might have specified some constraints on budget too.
The pass-through is the translation. It does not expose the ticket number or the cooking time…. it presents the finished dish. The UX equivalent is what we might call progressive disclosure of process — or, in many cases, the principled decision not to disclose process at all.
There is real design work here, and it is not trivial. The translation must be accurate. The user needs to know whether the agent succeeded or failed, and in cases of failure, needs enough information to intervene or redirect. But the translation must also be appropriately compressed, such as a summary of what was done, not a transcript of how it was done. In some cases where judgement has been applied, then a transparent rubric or evidence of sources balanced and weighed and how a conclusion formed from them. What was not included as well as what was, in such a judgement.
Amazon’s Alexa team documented early research into this problem in the context of voice interfaces, noting that users consistently rated verbose process narration as less trustworthy, not more — the opposite of what the design team had expected. Transparency, it turns out, is not the same as visibility. The diner trusts the kitchen not because they can see everything that happens in it, but because the plate in front of them is evidence that the kitchen worked.
3. Information boundary
The most philosophically interesting function of the pass-through is perhaps the one that is hardest to design. That is, the deliberate concealment of information that the user does not need, and would be harmed by receiving.
This is a deeply uncomfortable idea for UX practitioners who have been trained (ethically and correctly) in the principles of transparency and informed consent. We do not normally design systems that hide information from users. But the kitchen analogy is instructive here, because concealment in this context is not deception. It is curation.
Similar curation can be found in other fields of expertise. A surgeon does not narrate each incision to a patient under general anaesthesia. A pilot does not read aloud the hydraulics checklist during cruise. A solicitor does not copy their client on every internal email during case preparation. These are not failures of transparency; they are professional judgements about the information boundary appropriate to the relationship. The agent is working on behalf of the user. Like a surgeon, it operates best when not interrupted. Like a solicitor, its working notes are not the client’s deliverable.
The challenge for UX is that we must design this boundary with precision. Too much concealment, and the user loses the sense of agency and oversight that makes AI trustworthy. Too little, and we have recreated the kitchen in the dining room — all noise and heat and urgency, and the experience is ruined.
When the kitchen sends out the wrong dish
No metaphor survives contact with failure quite like a restaurant one.
Yeah, kitchens make mistakes. Dishes arrive cold, or incomplete, or not what was ordered. When this happens in a well-run restaurant, the front-of-house team has a protocol: acknowledge the error without drama, retrieve the dish, return with the correction. The pass-through, in these moments, works in reverse where information flows from the dining room back to the kitchen.
It turns out Agentic systems fail too. And sometimes they fail hard. They misinterpret instructions, get stuck in loops, take actions that seemed reasonable given their instructions but that the user would not have sanctioned. They hallucinate and make stuff up. They encounter edge cases that their designers did not anticipate and fail to surface.
The design question is: what does the reverse-pass look like?
This is perhaps the most underdeveloped area of agentic UX at present. Most current implementations handle failure pretty poorly, either by surfacing too much technical detail (the user is handed the raw error log, which is the equivalent of being taken into the kitchen to inspect the broken sauce) or by concealing failure entirely until it is too late to correct.
Good failure design in agentic systems requires the same qualities as good failure recovery in a restaurant: legibility, speed, and grace. The user needs to understand, at a high level, what went wrong. They need a clear path to correction. And they need the experience of failure to be contained and not to contaminate their overall relationship with the system.
What the pass-through reveals about trust
Perhaps there is a reason the restaurant metaphor maps so cleanly onto this problem. Both are service relationships characterised by what sociologists call asymmetric expertise. This is when one party knows far more about the process than the other, and the relationship functions precisely because the expert party uses that knowledge on behalf of the less-informed party.
Trust in these relationships is built at the pass, not in the kitchen. The user never sees the agent’s chain-of-thought. They never see the tool calls, the sub-agent instructions, the intermediate retrieval steps, the failed attempts. What they see is the output, and their assessment of the system’s trustworthiness is formed almost entirely on that basis.
This places an enormous burden on the pass-through as a designed artefact. It must communicate not just the result but the character of the process such as the fact that it was careful, that it was faithful to the user’s intent, that it can be relied upon again. In restaurant terms, the server is not just delivering food, they form part of the embodiment of the kitchen’s standards. The pass is the point at which the kitchen’s competence becomes visible, legibly and briefly, before being consumed.
Photo by Louis Hansel on Unsplash
For UX practitioners, this means that the summary, the confirmation, the status indicator, the completion screen etc (all these small moments of interface that come at the end of an agentic process) carry disproportionate weight. They are and should not be afterthoughts. Arguably, they are the pass.
Design principles for the pass-through interface
Drawing this together into practical guidance, several principles emerge.
Design the pass, not just the kitchen. The user’s primary interface with an agentic system is not its internal workings but its outputs and its completion states. Invest design effort accordingly. The visual language, the copy, the interaction model at the point of delivery matters more than the visualisation of intermediate steps.
Know what deserves a quality check. Not every agent action warrants a confirmation dialogue. Design for the distinction between reversible and irreversible actions, between low-stakes and high-stakes outputs. An agent that asks permission for everything has designed away its own utility. An agent that never pauses is one bad instruction away from a serious error.
Translate faithfully but sparingly. Users need enough information to trust the output and to identify failure. They do not always need a full log. Design completion states that communicate confidence, accuracy, and scope without recreating the process.
Design the reverse pass. Error states and recovery flows deserve the same design attention as success states. Failure should not be an edge case when designing agentic systems, but a design constraint. Users who are able to recover gracefully from failure trust the system more, not less. Having tools for the user to provide feedback in a language they understand, but is meaningful to the system.
Respect the information boundary. The goal is not maximum transparency; it is appropriate, curated, transparency. The user’s relationship with an agentic system is a service relationship. Design for the experience of being well-served, not for the experience of being fully informed.
A final word on the kitchen itself
It’s worth calling out finally, that there is a school of restaurant design that focusses on open kitchens, chef’s tables, live fire grills positioned theatrically at the centre of the room. This design intends to deliberately collapse the pass-through. In this relationship, the kitchen is intended to be the experience, so that the process is the product.
I suspect that there will be agentic products that work this way too, where a system’s orchestration is visible, where the user can watch the agent think, where the intermediate steps are part of the value. For certain professional tools, for certain expert users, this is a legitimate and interesting design direction.
But I caveate that I don’t think it will be the default. For most users, in most contexts, the kitchen should remain the kitchen. The pass-through should remain narrow. The dining room should be calm.
Our job, as UX practitioners, is therefore to design the window, and to accurately understand that what it conceals and what it reveals.
Photo by Martin Widenka on Unsplash
Further reading
- Lilian Weng, ‘LLM-Powered Autonomous Agents’, Lil’Log, 2023. Available at: lilianweng.github.io
- Nielsen Norman Group, ‘AI Agents: Key Concepts and Emerging UX Patterns’, nngroup.com, 2024
- Anthropic, ‘Building Effective Agents’, Anthropic Documentation, 2024. Available at: docs.anthropic.com
- Don Norman, The Design of Everyday Things, Basic Books, 2013 — particularly the chapters on affordances and feedback loops, which map cleanly onto agentic interaction models
- Alan Cooper, Robert Reimann, David Cronin & Christopher Noessel, About Face: The Essentials of Interaction Design, 4th edn, Wiley, 2014
메타데이터
- post_id
- 22b1412e6479
- slug
- designing-the-pass-through-in-agentic-computing-22b1412e6479
- url
- https://medium.com/design-bootcamp/designing-the-pass-through-in-agentic-computing-22b1412e6479
- canonical_url
- https://medium.com/design-bootcamp/designing-the-pass-through-in-agentic-computing-22b1412e6479
- author_url
- https://medium.com/@acutt
- status
- ok
- fetched_at
- 2026-06-09 15:37:30