MONOSIGN · Agent approvals

Sensitive AI actions.Your approval first.

WHAT IT IS. WHAT IT DOES.

Agent approvals hold sensitive tool calls for an accountable person’s decision before execution.

For teams responsible for production systems

EXAMPLE SCENARIO · THE GOAL

Let an agent restart a production service only after its owner decides.

Operations agent · Approver: Alex Morgan
The agent proposes a restart.

A production service would be affected. The request is created but has not reached the target.

Monofor/ AI SecurityDemo environment
Requested actiondeployment.restartProduction
REQUESTING AGENTrunbook-agentOwner: Platform team
CONTROL POINTMonoforIdentity & policy
TARGET TOOLMCP serverAwaiting decision
Agent identity···
Tool permission···
Human approval···
AMOwner approvalThe production service will restart.
tool.call.pendingEvaluating policy
Interactive example · No real actions
THE INTENDED OUTCOME

Approval lets the call proceed. Rejection prevents execution on the target.

Human-in-the-loopScoped delegationDeny on timeout

CONNECTED CONTROLS

Autonomy has limits.
Make them explicit.

Approval is a control before execution. A request never becomes permission simply because nobody answered.

01

Approval before execution

Route destructive or sensitive tool calls to the agent’s owner before they proceed.

  • Policy-defined approval requirements
  • Caller, tool, and request context
  • Explicit approve or reject decisions
02

Permissions intersect

An agent acting for a user is constrained by both identities.

  • On-behalf-of identity provenance
  • Agent ∩ user effective permissions
  • Per-user usage budgets
03

Reach the responsible person

Bring approval requests into the channels teams already use.

  • Management inbox
  • Email and push notifications
  • MCP-native approvals
04

Silence does not grant access

Keep a clear record of why a call proceeded or stopped.

  • Rejection blocks the call
  • Expiry and timeout deny access
  • Approval decisions in the audit trail

HOW IT WORKS

A deliberate pause before a sensitive action.

Connect to your identity infrastructure. Define your access policy. Keep each step visible.

Plan it with us
THE WORKFLOW, END TO END

The agent proposes an action within the applicable identity and tool policy.

The responsible person sees the caller, requested action, and context.

Approval allows the governed call to proceed. Rejection or timeout blocks it.

THE OUTCOME YOU ARE WORKING TOWARD

Approval lets the call proceed. Rejection prevents execution on the target.

MONOFOR · AI SECURITY

Make room for AI. Keep control.

Build the right identity and access approach for your agents.