Approval gates
Dual control, for agents.
Sensitive agent actions wait for a named reviewer before they run. The decision, the rule that fired, and the reviewer’s rationale land in the audit record — evidence for human-oversight and separation-of-duties controls.
Approval gates ship in the customer-cloud distribution. The public CLI records telemetry.
Approval queue
FinCard demo

Tool call, risk, and reviewer decision — every resolution lands in the audit trail.
01Controls evidenced
Three controls, one gate.
The same approval record answers an EU AI Act oversight test, an FFIEC dual-control test, and a DORA fail-closed test.
- EUAI.ART14-03Implementation evidence
Human-in-the-Loop Oversight & Rationales
EU AI Act Article 14: Human Oversight & Interventions
Catalog entryHow the session record supports it
Runtime sensitivity can hold specified tool calls. The approval ledger records reviewer decisions and available rationale.
Approval Decision Records / Deviations Review Queue
- FFIEC.SOD-01Implementation evidence
Dual-Control & Separation of Duties
FFIEC Information Security Handbook: Separation of Duties & Access Governance
Catalog entryHow the session record supports it
Role checks separate development and approval permissions. The approval contract can require an independent second review.
Portal Access Control / Approval Decision Ledger
- DORA.RES-03Implementation evidence
Fail-Closed Operational Resilience
DORA Article 11: Response & Recovery with Fail-Safe Controls
Catalog entryHow the session record supports it
The runtime approval provider fails closed on timeout or transport error. The portal records blocked actions when configured.
Runtime Approval Provider / Risk-Prevented Ledger
02Decision loop
How every tool call gets evaluated.
Deterministic rules decide first; the sensitivity gate weighs tool metadata, policy overrides, and prior approvals. The runtime is the source of governance truth.
01
Intercept
Catch the tool call before a bad change lands.
02
Classify
Score risk using tool metadata, policy rules, and approval history.
03
Enforce
Allow, confirm, or block, then record the outcome for audit.
Allow
Low-risk reads and deterministic checks run straight through.
Confirm
Execution pauses until a named reviewer approves or denies, with rationale.
Block
Policy violations stop before the action executes. The block is recorded.
03The problem
The problem isn’t AI agents. It’s that nobody can answer for what they did.
- Engineers keep their tools
- Security keeps the gate, on the agents your team already runs.
- Approve before it executes
- Destructive commands and external writes pause for explicit confirmation.
- One policy across every repo
- Same rules, budgets, and audit format on laptop, CI, and cloud workers.
04Deployment
Validated on AWS today
Bedrock inference on your AWS credentials and IAM-scoped workers in your account. One-stack deployment of the portal and audit store is still in progress; Azure and Google Cloud adapters are roadmap.
Full architecture detail lives in the cloud deployment section.
Try it on one repo
Prove approvals, audit, and policy on one real workflow — and walk away with the evidence for the oversight controls above. Then roll it out.