Outcome
Destructive MCP tool calls require an explicit human decision and cannot execute when approval is missing, invalid, rejected, or expired.
Scope
- Conversational held-stream approvals for attended sessions.
- Webhook approvals for unattended operation.
- Durable parking, argument binding, and exactly-once execution.
- Trusted decision ingress and webhook egress.
- Header and reasoning propagation needed by approval UX.
- Client-side tool approvals.
- Parked approvals remain alive without being mistaken for stuck calls.
Complete when
- Approval policy identifies every gated call before execution.
- Approve executes the bound call once; reject and timeout fail closed.
- Decisions are bound to the intended run, tool, and arguments.
- Duplicate or replayed decisions cannot execute a call twice.
- Supported approval paths have end-to-end integration coverage.
Architecture: #255 and PR #256.
Outcome
Destructive MCP tool calls require an explicit human decision and cannot execute when approval is missing, invalid, rejected, or expired.
Scope
Complete when
Architecture: #255 and PR #256.