Approvals

Every change ships as a content-hashed plan a human accepts. Approval issues a single-use token bound to the plan — if any input drifts after you approve, apply refuses.
Pending
3
1 destructive · 1 incident remediation · 1 containment
Oldest waiting
11h
plan-9107 — held for change window, re-queued 09:00
Decided today
2
1 approved · 1 denied (change window)
Median time-to-decision · 30d
26m
every decision lands in the audit trail
pl-88c1destructive

Reconcile — delete 2 orphaned resources

verde-foods / prod · drafted by reconcile controller · 13:47 today
plan-9107remediation

Raise search memory 2Gi → 4Gi

kestrel-bank / prod · copilot ⇒ priya.n · from INC-241 · waiting 11h
pl-c214containment

Terminate labs-worker-1 · revoke session · quarantine image

kestrel-bank / prod · security controller · rule CF-R-114 · 13:58 today
The token is an HMAC over (plan, caller, expiry) — single-use. A bare "yes" never qualifies; a drifted plan fails closed. Copilot cannot mint its own token.

Plan pl-88c1

Awaiting approval verde-foods / prod
Checks
Exactly what executes


        
Evidence & verification

Recently decided

decisions are audit entries — see Security → Audit trail
PlanChangeDecisionByOutcome
pl-9f2e41Upgrade 0.1.88 → 0.1.91 · meridian-health/prod approved 14:01kai.tran token consumed by run-8842 · running
plan-9107Search memory 2Gi → 4Gi · kestrel-bank/prod denied 08:40a.mora held for change window · re-queued 09:00 (pending above)
pl-4te7c2New staging environment · tern-aviation (copilot-drafted) awaiting requesterkai.tran apply refused without token · see session
Demo · act as