4.0Approve
Review sensitive actions before they run
Compare the current record with the proposed change, then release or hold it. The server records the decision with your name and timestamp on every plan.
Now
- order ORD-4471
- buyer d.harper
- value £42.60
- status fulfilled
- carrier network, delivered Tue
- claim none
- refund none
- buyer_reply none
- stock unchanged
- owner unassigned
- record none
If you approve it
- order ORD-4471
- buyer d.harper
- value £42.60
- status exception
- carrier network, postcode mismatch
- claim CLM-88104, opened 14:02
- refund £42.60 ← waiting on you
- buyer_reply drafted by Mira, not sent
- stock unchanged
- owner you
- record released_by · released_at
Whatever you pick is written on the order: what was asked, who decided, when.
Press either one. Approve applies the change and signs it; Reject applies nothing.
Audited on 2026-08-21: no part of the gate lives in client JavaScript. Disabling scripts in the browser bypasses nothing, because the browser is not what is holding the action.
The gate
A gate for each agent
Each agent carries its own spending ceiling, starting at zero. Actions above that ceiling are written down and wait for a person on every plan, including the free one.
- 4.1What stopsSpend, refunds, supplier commitments, price changes, cancellations and anything that leaves the workspace under your name.
- 4.2On every planFree and paid plans use the same hold for the same actions.
- 4.3Enforced on the serverThe backend enforces the hold. It also applies to direct API calls and work started from your own code.
Deciding
See the proposed change
An approval that shows you a sentence about what will happen is asking you to trust the summary. Hawi shows the record as it is and as it would be, side by side, with the figures that moved highlighted — so the thing you are approving is the thing you looked at.
- 4.4Before and afterThe order, the listing or the reply in both states. No summary standing in for the actual change.
- 4.5Why it was proposedWhat the agent read and what it concluded are attached to the proposal. You can challenge either the reasoning or the outcome.
- 4.6Amend the proposalChange the figure, review the revised version and release it from the same screen.
- 4.7AnywhereApprovals reach you on the dashboard, by mail and on your phone. A gate you can only clear at a desk is a gate that gets left open.
The record
A record you can return to
The record keeps what was asked, who released it, when, and what it looked like at the time. A supplier dispute or audit can be checked against the order itself.
- 4.8Named decisionEvery approval carries the person's name, the workspace and the timestamp.
- 4.9PermanentA released approval is not editable afterwards. Corrections are new records that reference the old one.
- 4.10Automatic settlementLetting an agent settle small amounts unattended is a separate permission with its own switch and its own ceiling, acknowledged explicitly.
The rest of the system
- 1.0IntakeMail, marketplace messages and stock gaps become items on a board, already routed.
- 2.0WatchCover counted against what is selling, so a line that runs out is flagged early.
- 3.0ActNamed agents work the item and hand it between themselves with the evidence attached.
- 5.0MonitorWhat moved, what is stuck, and what is waiting on you — with the numbers behind it.
- 8.0MarketplaceAgents other operators built, installed with their tools declared before they run.
- 9.0LimitsA ceiling on what runs unattended, and the actions no ceiling ever covers.
- 10.0BoardsOne board held by people and agents alike, where the column follows the owner.
- 11.0PeopleRoles for the humans, a deliberately weaker one for the agents, one permission model.
- 12.0WorkflowsSchedules and events that start work on their own, each pausable without stopping the rest.
Start with one agent and one job.