Skip to content

[EPIC] Agent Workflows #384

Description

@Shearerbeard

Overview

HITL today approves one tool call at a time, mid-execution, while an SSE stream
holds the request open. That works attended, but it's the wrong shape for
unattended remediation: an SRE wants the whole proposed sequence in front of
them - the exact calls in order, each with its intent and read/write class -
so they can approve it the way they'd approve runbook steps, before
anything runs.

The goal is for the agent to assemble that sequence itself: a reviewable
workflow of exact tool calls with per-step intent (we already force
_aura_reasoning on orchestration tool calls), destructive steps gated. AURA's
half of the equation is inputs and outputs: emit the proposal over the HITL
webhook with enough context and intent that the receiving side can make a real
approval decision. The decision comes back, and only the approved version
executes.

This builds directly on shipped HITL: the approval exchange plus header
forwarding (#276) and intent forwarding (#277) are the same wires this needs.

User outcome

An SRE (or a governance layer acting for one) can:

  • See the proposed workflow before execution: ordered calls, arguments,
    per-step intent, which steps are destructive
  • Approve or deny the exact sequence, knowing the approval is bound to that
    version and any drift from it fails closed

Scope notes

Activity

  1. changed the title [-][EPIC] Agent-proposed tool workflows with SRE approval[/-] [+][EPIC] Agent-proposed tool workflows with SRE approval (governance)[/+] on Jul 17, 2026
  2. changed the title [-][EPIC] Agent-proposed tool workflows with SRE approval (governance)[/-] [+][EPIC] Agent Workflows[/+] on Aug 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions