Private Alpha

Approval governance

How Ethen manages human-in-the-loop approvals, risk classification, policy enforcement, and evidence trails.

Raw

Ethen's approval framework provides human-in-the-loop (HITL) controls for sensitive actions, with configurable policies, risk classification, evidence collection, and audit trails.

Risk classification

Every tool action is classified into a risk level. Each risk level maps to a user-facing label:

Risk levelLabelExample actions
read_onlyRead OnlyReading files, fetching data
write / writes_user_contentWrites DataCreating or editing content
external_side_effectExternal EffectSending API requests, posting to external services
destructiveDestructiveDeleting resources, modifying critical state
privilegedPrivilegedAccessing credentials, modifying policies

Approval policies

An approval policy (ApprovalPolicy) governs when human approval is required:

Policy fieldDescription
nameHuman-readable policy name
descriptionPolicy summary
riskThresholdActions at or above this risk level require approval
requireApprovalForSpecific risk levels that always require approval
blockActionsRisk levels that are blocked outright
autoExecuteRiskLevelsRisk levels that may auto-execute without approval
maxAutoExecuteCountMaximum auto-executions before approval is required
requireJustificationWhether a justification is required
escalationContactContact for escalation when approval is needed

Approval lifecycle

An approval request progresses through these states:

text
draft → pending → approved → executed
         ↓          ↓
      rejected   cancelled
         ↓
      expired / stale / blocked
StatusDescription
draftProposal created but not yet submitted for review
pendingAwaiting human decision
approvedHuman approved the action
rejectedHuman rejected the action
cancelledThe request was cancelled before resolution
expiredThe request's expiry time passed without a decision
blockedPolicy prohibits the action
staleThe request's payload hash no longer matches the current state

Decision types

A human reviewer can submit one of four decision types:

DecisionEffect
approveApproves the action for execution
rejectRejects the action
escalateForwards the decision to the escalation contact
deferDelays the decision

Each decision is recorded with the actor's identity (ID, name, role), an optional comment, and a timestamp.

Payload hash binding

When an approval request includes a payloadHash (SHA-256 of the approved content), the system can detect if the underlying payload has changed since approval. A status of stale indicates the payload no longer matches the hash — the request must be re-submitted.

Evidence package

An approval request can carry an evidence package — a set of supporting materials for the reviewer:

Evidence fieldDescription
labelHuman-readable label
contentUrlURL to full evidence content (nullable)
summaryPlain-English summary of what was observed
confidenceConfidence level (high, medium, low)
sourceNameOrigin of the evidence
freshnessHow current the evidence is (ISO timestamp, nullable)
verifiedWhether the evidence has been independently verified

Audit trail

Every event in the approval lifecycle produces an ApprovalAuditRecord:

Audit eventDescription
createdApproval request was created
submittedRequest was submitted for review
decidedA decision was recorded
escalatedThe request was escalated
expiredThe request expired
cancelledThe request was cancelled

Each audit record includes the actor identity (when applicable), a detail string, and references to evidence items.

Review-required statements

The following aspects of the approval governance framework have not been independently verified:

  • Policy enforcement boundaries: the actual enforcement of blockActions and autoExecuteRiskLevels depends on the runtime environment and has not undergone independent penetration testing.
  • Evidence package confidence scoring: the confidence field reflects heuristic classification and is not a certified accuracy metric.

See also

Last verified 2026-07-10 · Owner platform-team