Steerable Pentesting · Human on the Loop

Steerable pentesting: autonomy you can direct

The industry keeps arguing the same binary: fully autonomous AI versus fully manual human testing. Both are the wrong question. The right model is a steerable autonomous agent, one that runs on its own but that a practitioner can pause, redirect, and validate on demand. Autonomy's breadth and human judgment, in the same system. This is the third category, and it is where continuous offensive security is heading.

The False Binary

Fully autonomous or fully manual is the wrong choice

The market has organized itself around two poles, and vendors compete to sit at one end or the other. But the poles describe a tradeoff, not a product. Each extreme gives up exactly what the other is good at.

Pole One

Fully autonomous, no human in the path

An agent that runs entirely on its own buys you breadth and constancy: it watches an attack surface that changes daily and tests it without waiting for anyone. That is real, and it is valuable. What it gives up is direction. No one can point it at the business logic flaw that needs a human's intuition, no one can redirect a run that is circling the wrong target, and nothing it reports carries a practitioner's signature. When the whole promise is "no humans," there is no one to steer when steering is exactly what a hard target needs.

Pole Two

Fully manual, humans in every step

A human penetration test delivers depth and judgment: senior practitioners chase chained abuse, reason through hard targets, and sign an accountable result. That is also real, and also valuable. What it gives up is pace. A person-driven engagement is a point-in-time snapshot that arrives once or twice a year, priced and scheduled so that it cannot track a surface which changes with every deployment. By the time the report lands, the environment it describes has already moved.

Framed as a choice between these two, a buyer is forced to trade breadth for judgment or judgment for breadth. The better programs already refuse the trade and run both, awkwardly, as separate line items. The category has simply not named what running both, in one system, looks like.

The Third Category

Steerable: an autonomous agent a human can direct

Steerable pentesting keeps autonomy as the default and adds a human on the loop. The agent plans and runs the full assessment by itself. A practitioner supervises, and can step into any run to steer it, without slowing the runs that do not need steering.

The distinction that matters is human-on-the-loop, not human-in-the-loop. Human-in-the-loop means a person approves each step, which throttles the agent back to human speed and defeats the point of automation. Human-on-the-loop means the agent runs autonomously and a person supervises with the authority to intervene at any moment. Autonomy is the default. Intervention is the option.

That single design decision is what lets one system hold both ends of the old binary. The breadth comes from the agent running continuously on its own. The judgment comes from a practitioner who can direct it toward what autonomy alone would miss, and put a signature on what comes back.

  • Runs autonomously. The agent discovers, maps, tests, and chains on its own, continuously, without a person driving each step.
  • Steer any run. A practitioner can point the agent at a specific target, technique, or abuse case the moment a run needs direction.
  • Pause and redirect. Stop a run instantly, hand it a business logic path the agent would not reach on its own, and let it resume from there.
  • Validate before delivery. Route any finding, or an entire run, through a senior practitioner for an accountable sign-off before it reaches your team.

Agent runs

The autonomous operator works the full sequence on its own: inventory, attack surface, fingerprinting, testing, and chaining, at machine pace and machine breadth.

Practitioner watches

A senior tester is on the loop, seeing what the agent sees. Nothing waits on their approval, but nothing is beyond their reach either.

Steer where it counts

When a run needs a human's intuition, the practitioner pauses it, redirects it toward the business logic or chained abuse the agent would not argue its way into, and lets it continue.

Validate and deliver

Findings are reproduced by the agent and, on demand, validated by the practitioner before they land, so what reaches you carries both proof and, where you want it, a signature.

Why Now

The extremes are already showing their limits

This is not a thought experiment. Through the first half of 2026 the market itself has been drifting off both poles, from opposite directions, toward the middle the category has not yet named.

The autonomous pole retreats

Pure self-serve autonomy hit a ceiling

XBOW, one of the most visible names betting on fully autonomous, self-serve testing, pulled back from that pure position toward a human-in-the-loop model in mid-2026. When a well-funded proponent of the no-human extreme adds people back into the path, it is direct evidence that the extreme has limits: some findings need direction, some results need a signature, and some judgment does not automate away. The lesson is not that autonomy failed. It is that autonomy without a human to steer it leaves value on the table.

The manual pole can't keep pace

Human PTaaS can't track continuous change

At the other end, human-delivered testing, however good, is structurally point-in-time. Modern attack surfaces change with every deployment, and a person-driven engagement priced and scheduled a few times a year cannot follow that. Buyers feel the gap directly: the report is accurate the day it ships and stale the week after. Adding more human hours does not close a pace problem, it just raises the price of a snapshot.

Both poles are converging on the same answer from opposite sides. The autonomous camp is adding humans; the human camp needs autonomy to keep up. Steerable pentesting is simply the name for the destination they are both moving toward: autonomy by default, human judgment on demand.

What It Buys You

What steerability actually delivers

Steerability is not a feature bolted onto autonomy. It is what turns a fast, broad agent into a testing program you can stand behind.

  • Autonomous and steerable. The agent runs the full sequence on its own, and a practitioner can direct any run.
  • Proof, not probability. Every finding ships exploit-proven, with the requests, responses, and steps that reproduce it.
  • Human validation on demand. Put a senior tester's signature on any finding, or an entire run, before it lands.
  • Continuous by default. Coverage tracks a changing attack surface instead of the calendar.
In Practice

Planck Operator is steerable by design

Planck Operator is an autonomous penetration testing agent built human-on-the-loop from the start. It discovers, tests, and chains on its own, continuously, and a senior offensive security team can steer any run, pause it, redirect it at business logic, and validate a result before it reaches you. It is what the third category looks like when it ships.

FAQ

Steerable pentesting, common questions

What is steerable pentesting?

Steerable pentesting is autonomous penetration testing that a human can direct. The agent plans and runs the full assessment on its own, but a practitioner can pause any run, redirect it toward a business logic path the agent would not reach, and validate findings before they are delivered. It combines the breadth and constancy of autonomy with human judgment available on demand.

How is steerable pentesting different from fully autonomous pentesting?

A fully autonomous pentester runs without a person in the path. That gives you breadth and speed, but no one can redirect it toward the abuse cases that require human intuition, and nothing carries a practitioner's signature. Steerable pentesting keeps the autonomy and adds a human on the loop: the same continuous agent, plus the ability to intervene, steer, and sign off when it matters.

Is human-on-the-loop the same as human-in-the-loop?

No. Human-in-the-loop means a person must approve each step, which throttles the agent back to human speed. Human-on-the-loop means the agent runs autonomously by default and a person supervises, able to step in at any point. Steerable pentesting is human-on-the-loop: autonomy is the default, intervention is the option.

Why does steerability matter for penetration testing?

Autonomy is strongest on breadth: continuous discovery and testing across a changing attack surface. Human judgment is strongest on depth: business logic, creative abuse, and the accountable sign-off a framework or a board requires. Steerability lets one system deliver both, because a practitioner can direct the agent into the places autonomy alone does not reach and validate what comes back.

Does steerable pentesting slow the agent down?

No. Because it is human-on-the-loop rather than human-in-the-loop, the agent runs at full autonomous speed and continues without waiting for approval. Steering is an option a practitioner exercises when a run needs direction or a finding needs a signature, not a gate every step has to pass through.

Where can I see this in a product?

Planck Operator is our steerable, human-on-the-loop agent. It runs autonomously and continuously, and a senior team can steer any run, pause it, redirect it at business logic, and validate findings before delivery. See Planck Operator for how it runs, or read what agentic pentesting is for the broader category.

Get Started

Autonomy you can steer, on your attack surface

Give us a domain and the rules of engagement. We will return a scoped run, show you what the agent surfaces on its own, and where a practitioner steers it.