New One-call approvals are live in the console
One-call approvals

Say yes to this. Not to everything like it.

When something needs a person, the person sees the actual call — the tool, the wording, the amount — and decides that one. The next identical request asks again. An approval that covers a category is not an approval; it is a permanent exception with a friendly name.

Waiting on you
create_ticket14:02
subject: "Card declined on renewal" · priority: high
create_ticket14:09
subject: "Duplicate charge" · priority: high
Two calls to the same tool, in the same session, by the same person.
02 What the decision is tied to

Four things pin an approval down

Change any one of them and it is a different call, needing a different answer.

Who asked

The person behind the agent, by name.

Which session

The window it was asked in.

Which tool

The one action, not the app.

The exact request

The wording and values, fingerprinted.

03 Afterwards

The decision is evidence, either way

Approve or deny, it is written down the same as any other call — with the name of whoever decided.

Approval approval-118 allowed

One create_ticket call, decided by a named person before it was allowed out.

Requested by ana.duarte@northwind.co
Approved by marc.leduc@northwind.co
Tool create_ticket
Covers this call only
Next step

Where to go next

Two readers, two different next steps.

Security leader

See how the controls hold up in a review.

Platform engineer

Connect any client to the same address.