Approval gates

Dual control, for agents.

Sensitive agent actions wait for a named reviewer before they run. The decision, the rule that fired, and the reviewer’s rationale land in the audit record — evidence for human-oversight and separation-of-duties controls.

Approval gates ship in the customer-cloud distribution. The public CLI records telemetry.

Approval queue

FinCard demo

Verification portal approvals queue with reviewer rationale and audit trail.

Tool call, risk, and reviewer decision — every resolution lands in the audit trail.

01Controls evidenced

Three controls, one gate.

The same approval record answers an EU AI Act oversight test, an FFIEC dual-control test, and a DORA fail-closed test.

  1. EUAI.ART14-03Implementation evidence

    Human-in-the-Loop Oversight & Rationales

    EU AI Act Article 14: Human Oversight & Interventions

    How the session record supports it

    Runtime sensitivity can hold specified tool calls. The approval ledger records reviewer decisions and available rationale.

    Approval Decision Records / Deviations Review Queue

    Catalog entry
  2. FFIEC.SOD-01Implementation evidence

    Dual-Control & Separation of Duties

    FFIEC Information Security Handbook: Separation of Duties & Access Governance

    How the session record supports it

    Role checks separate development and approval permissions. The approval contract can require an independent second review.

    Portal Access Control / Approval Decision Ledger

    Catalog entry
  3. DORA.RES-03Implementation evidence

    Fail-Closed Operational Resilience

    DORA Article 11: Response & Recovery with Fail-Safe Controls

    How the session record supports it

    The runtime approval provider fails closed on timeout or transport error. The portal records blocked actions when configured.

    Runtime Approval Provider / Risk-Prevented Ledger

    Catalog entry

02Decision loop

How every tool call gets evaluated.

Deterministic rules decide first; the sensitivity gate weighs tool metadata, policy overrides, and prior approvals. The runtime is the source of governance truth.

  1. 01

    Intercept

    Catch the tool call before a bad change lands.

  2. 02

    Classify

    Score risk using tool metadata, policy rules, and approval history.

  3. 03

    Enforce

    Allow, confirm, or block, then record the outcome for audit.

Allow

Low-risk reads and deterministic checks run straight through.

Confirm

Execution pauses until a named reviewer approves or denies, with rationale.

Block

Policy violations stop before the action executes. The block is recorded.

03The problem

The problem isn’t AI agents. It’s that nobody can answer for what they did.

Engineers keep their tools
Security keeps the gate, on the agents your team already runs.
Approve before it executes
Destructive commands and external writes pause for explicit confirmation.
One policy across every repo
Same rules, budgets, and audit format on laptop, CI, and cloud workers.

04Deployment

Validated on AWS today

Bedrock inference on your AWS credentials and IAM-scoped workers in your account. One-stack deployment of the portal and audit store is still in progress; Azure and Google Cloud adapters are roadmap.

Full architecture detail lives in the cloud deployment section.

Try it on one repo

Prove approvals, audit, and policy on one real workflow — and walk away with the evidence for the oversight controls above. Then roll it out.