A human in the loop adds minutes to recovery
Manual failover exists because a person can weigh what a health check cannot, such as whether losing the last few seconds of writes is acceptable for this data today. That judgement costs time, and the time belongs in the RTO.
Google's SRE book states it plainly: humans add latency. Its on-call chapter gives typical paging targets of five minutes for user-facing services and thirty for less urgent ones, and that covers only the wait until someone starts working. Confirming the problem, opening the runbook and acting come after.
Access matters too. The Financial Times copied its runbooks to S3 so they would survive an outage, then found during a single sign-on failure that the copies sat behind that same sign-on and nobody could open them. Whatever the responder needs and shares fate with the failure is The dependency you did not list.
A reasonable middle ground, and the one AWS recommends, is to automate every step so that starting failover is like pressing a button, leaving a person only the choice to press it (Failover is a decision, not an event). Preparation shortens that choice too: the SRE book reports roughly a threefold improvement in time to repair when responders work from a playbook rather than improvising.