Docs / Concepts

Approvals

Require a human to approve sensitive agent operations. The broker holds the request, a person decides in the dashboard, and the broker executes exactly what was approved.

Mark a rule with "require_approval": true and every matching call waits for a person. The broker executes the operation with exactly the parameters that were approved.

The flow

  1. The agent calls POST /v1/actions. The broker answers 202:
    {"status": "approval_required", "request_id": "8a41d0c2", "poll": "/v1/actions/8a41d0c2"}
  2. The request appears in Approvals with the agent, operation and parameters.
  3. Someone approves or denies it.
  4. The agent polls GET /v1/actions/{id}. While waiting it sees pending; after approval the first poll executes the operation and returns the result. A denial returns denied.

Guarantees

  • The approved parameters are fingerprinted; a different call cannot ride on an approval.
  • An approved request executes once.
  • Requests expire if nobody decides.
  • A lockdown blocks execution even of approved requests.

The MCP tools expose the same flow: pastkeys_execute returns approval_required, and pastkeys_check_operation polls.