Enterprise early access is open. Request access

Docs Tasks Require approval for an action

Require approval for an action

Make a capability pause for a human decision instead of running. The request waits, an approver decides, and both the wait and the decision are recorded.

Before you begin#

  • The approval module enabled, with durable storage if approvals should survive a restart.
  • A working allow rule — see Write a policy that allows traffic. Approval rules are evaluated after deny and allow rules, so a request that would be denied never reaches them.

Add an approval rule#

This pauses refunds above a cost threshold while leaving smaller ones flowing:

policy:
  rules:
    defaultDecision: deny
    allowedTenants: [retail]
    allowedCapabilities: [refund-processing]
    approvalRules:
      - capability: refund-processing
        maxCostUsd: 1000
        approvers: [commerce-ops]
        reason: High-value refunds need a second pair of eyes.
        ttlSeconds: 3600
helm upgrade agentfleet ./agentfleet \
  --namespace agentfleet-system --reuse-values -f my-values.yaml

Verify#

A request above the threshold returns 409 with approval_required instead of running:

{"error":{"code":"approval_required",
           "message":"This request is waiting for approval."}}
Check both directions

A request under the threshold should still return 200. If everything now needs approval, the rule is matching more broadly than you intended.

Decide the request#

Open Console → Approvals. Each pending item shows the agent, the action, the policy reason that triggered it, and a timeline. Approve or deny, optionally with a comment.

kubectl port-forward -n agentfleet-system svc/agentfleet-console 8089:8089 &
open http://127.0.0.1:8089
Approvals expire

ttlSeconds bounds how long a request stays actionable. An expired approval is a terminal state, not a silent allow — the caller gets approval_expired and has to ask again.

Notify someone#

Nobody watches an inbox. Point approvals at a webhook so a transition reaches wherever your team already works:

approval:
  notification:
    webhook:
      url: https://hooks.example.com/agentfleet-approvals

What the caller sees#

Approval is not a blocking call. The request returns 409 immediately with an approval reference; the caller polls or waits on the webhook rather than holding a connection open for an hour.