Skip to content

Approvals

Tools with risk_level write or financial, or requires_owner_approval: true, always need the owner’s approval for every call in the portal. Agents cannot approve — even under prompt injection, an agent can only create a pending request.

  1. The agent calls call_partner_tool → gets approval_required with approval_id, approve_url, expires_at (30 minutes).
  2. The agent tells the owner: “Please approve creating the watchlist at …”. Calling again with the same arguments while pending returns the same request.
  3. The owner opens the link, reads the exact arguments that will be sent to the partner, and taps Approve or Deny. Financial actions require signing in again within the last 5 minutes.
  4. The agent calls call_partner_tool again with the same arguments and the approval_id.
Rule Why
An approval only works for the exact arguments approved (compared by hash) The content cannot change after a human read it
Single use No unintended repeats
Expires after 30 minutes The decision belongs to its context

Breaking any of these → approval_invalid. Call again without approval_id to create a new request.