Human approval that means something
Approval is only a safeguard if it is independent, specific, fresh and single-use. SensCheck checks all four.
| Property | What is enforced |
|---|---|
| Independent | The approver must be a human, and not the principal that proposed the effect |
| Specific | The approval carries the effect digest. A changed effect has no approval |
| Fresh | It has an expiry, and a maximum age (15 minutes by default) |
| Single-use | An approval ID can be consumed once. A second use fails closed as a replay |
When approval is required
- A policy rule says
REQUIRE_APPROVALfor that kind of action. - The effect's risk is at or above the threshold (HIGH by default).
- A risk provider raised the risk. Providers can raise risk but never lower it.
Where approval comes from
You supply an ApprovalProvider. Free options: StaticApprovalProvider (your code records approvals), CallbackApprovalProvider (call your ticketing or chat system) and TerminalApprovalProvider (ask at the terminal). The agent must have no way to reach these.
What the agent sees
A blocked call throws GovernanceBlockedError with the decision and reason codes. Show a REQUIRE_APPROVAL to a person. Do not retry in a loop, and do not catch and carry on. Never turn a block into a success message the model might read as "done".
Honest caveat
A tired human clicking "yes" all day is a risk no SDK removes. Keep approvals rare (use risk levels well), specific (show what will happen) and reviewable (receipts).