Approvals
Tools with risk_level write or financial, or requires_owner_approval: true, always need the owner’s approval for every call in the portal. Agents cannot approve — even under prompt injection, an agent can only create a pending request.
- The agent calls
call_partner_tool→ getsapproval_requiredwithapproval_id,approve_url,expires_at(30 minutes). - The agent tells the owner: “Please approve creating the watchlist at …”. Calling again with the same arguments while pending returns the same request.
- The owner opens the link, reads the exact arguments that will be sent to the partner, and taps Approve or Deny. Financial actions require signing in again within the last 5 minutes.
- The agent calls
call_partner_toolagain with the sameargumentsand theapproval_id.
| Rule | Why |
|---|---|
| An approval only works for the exact arguments approved (compared by hash) | The content cannot change after a human read it |
| Single use | No unintended repeats |
| Expires after 30 minutes | The decision belongs to its context |
Breaking any of these → approval_invalid. Call again without approval_id to create a new request.
