Course Content
AI Safety & Guardrails
5 sections · 50 lessons
How do you design systems that support user appeals and feedback?
What you need to know
What the user needs
- Notice: that an automated system was involved, and the main reasons.
- A contest button on the decision itself — not a support email three clicks away.
- A human reviewer with authority to overturn.
- A timeline and an outcome: when they will hear back, and what changed.
GDPR gives people the right to human intervention and to contest solely automated decisions with significant effects; DPDP gives a right to grievance redressal; many sector rules require complaint handling.
What the system needs
- Decision ID — every consequential output has a stable ID that joins to its audit record.
- Review queue — the reviewer sees the input, retrieved context, guardrail results, model version and explanation.
- Recorded decision — the reviewer's outcome and reason are stored.
- Write-back — a reversal updates the record and every downstream system that used the original decision.
- Learning loop — overturned cases go into the eval and regression suite after review.
Write-back is where most designs break. If a loan rejection was already sent to a credit bureau or a CRM, overturning it in one system is not enough.
Feedback as a quality instrument
| Metric | What it signals |
|---|---|
| Appeal volume | Rising volume is often the first quality alarm |
| Overturn rate | High means the system is often wrong; near zero may mean reviews are not real |
| Overturn rate by group | A gap is a fairness finding |
| Time to resolution | Whether the process is usable |
Feedback is not training data yet
Thumbs-down, clicks and appeals are biased toward certain users and can be gamed. Review them and label properly before any training use.
A real-life example
An email assistant at a company automatically files incoming mail into folders and marks some as "spam — auto-deleted after 30 days". A sales manager discovers a client's purchase order was filed as spam and deleted.
The team adds a "Not spam" button on every auto-filed message that restores it and records the decision ID; a weekly summary email lists everything auto-filed as spam; auto-deletion now requires 60 days and no open threads with the sender; and overturned spam decisions feed a review queue where a person confirms before they are added to the eval set. In the first month, 140 overturns show that invoices from one payment platform are consistently misfiled, which is fixed with one rule.
Follow-up questions to expect
- "How do you stop appeals from overwhelming reviewers?" — Prioritise by impact, allow automatic reversal for low-risk cases, and fix the systematic causes that the appeals reveal.
- "Can an LLM help review appeals?" — It can summarise the case and suggest an outcome, but a human with authority must decide, or it is not an appeal.
- "What if the user is trying to game the system?" — Keep the reviewer's decision independent of how hard the user pushes, and watch for repeated appeals from the same accounts.