Overview
HITL today approves one tool call at a time, mid-execution, while an SSE stream
holds the request open. That works attended, but it's the wrong shape for
unattended remediation: an SRE wants the whole proposed sequence in front of
them - the exact calls in order, each with its intent and read/write class -
so they can approve it the way they'd approve runbook steps, before
anything runs.
The goal is for the agent to assemble that sequence itself: a reviewable
workflow of exact tool calls with per-step intent (we already force
_aura_reasoning on orchestration tool calls), destructive steps gated. AURA's
half of the equation is inputs and outputs: emit the proposal over the HITL
webhook with enough context and intent that the receiving side can make a real
approval decision. The decision comes back, and only the approved version
executes.
This builds directly on shipped HITL: the approval exchange plus header
forwarding (#276) and intent forwarding (#277) are the same wires this needs.
User outcome
An SRE (or a governance layer acting for one) can:
- See the proposed workflow before execution: ordered calls, arguments,
per-step intent, which steps are destructive
- Approve or deny the exact sequence, knowing the approval is bound to that
version and any drift from it fails closed
Scope notes
Overview
HITL today approves one tool call at a time, mid-execution, while an SSE stream
holds the request open. That works attended, but it's the wrong shape for
unattended remediation: an SRE wants the whole proposed sequence in front of
them - the exact calls in order, each with its intent and read/write class -
so they can approve it the way they'd approve runbook steps, before
anything runs.
The goal is for the agent to assemble that sequence itself: a reviewable
workflow of exact tool calls with per-step intent (we already force
_aura_reasoningon orchestration tool calls), destructive steps gated. AURA'shalf of the equation is inputs and outputs: emit the proposal over the HITL
webhook with enough context and intent that the receiving side can make a real
approval decision. The decision comes back, and only the approved version
executes.
This builds directly on shipped HITL: the approval exchange plus header
forwarding (#276) and intent forwarding (#277) are the same wires this needs.
User outcome
An SRE (or a governance layer acting for one) can:
per-step intent, which steps are destructive
version and any drift from it fails closed
Scope notes
handling, execution binding. The review UX and routing live downstream.
hours on approval needs somewhere durable to live, which is the same parking
problem HITL V2 already has.