Skip to content

Approvals

Agent Guardrails → Approvals (Pro) holds agent actions that need a human decision. Approving runs the action once, as the agent, and the agent can poll for the result.

A request is created only when an agent attempts an action and the decision is Require approval, from either:

  • a policy rule whose Then is Require approval (for example the “Approve refunds over X” template), or
  • the agent’s permission for that ability set to Require approval.

Rules and permissions alone never create requests — an agent has to make a matching call. If the Approvals screen stays empty, check that:

  1. the rule applies to All agents or to the agent that is actually calling (a rule scoped to Site AI only covers AI features running inside WordPress);
  2. the agent is making calls at all — look in the Audit Log;
  3. the call matches the rule’s conditions (for example the refund is above the amount).

For each new request Raqvio Agent Guardrails sends:

  • an email “[Site name] Approval needed: ability” to the addresses in Settings → Notify these emails about new approvals, or the site admin email — with the agent, ability, risk, amount / percent change / item count / status where relevant, and the reason;
  • a Slack message, if you set a Slack incoming webhook. It contains no secrets and no full input.

Both carry two links: Approve or reject, which opens the approve-or-reject page, and Open the approval queue.

The admin bar shows the number of pending requests, and the dashboard shows “N approvals waiting for you”.

The list can be filtered by Agent, Ability and Status (Pending, All, Executed, Rejected, Expired, Failed). Review opens “Approval request #N”:

  • agent, ability and risk, Why (the rule or permission), requested and expiry times;
  • What will change — for example “regular_price: 10 → 40” and “Price change: 300%”, or for a refund “Order #5314”, “Refund amount: 150.00” and “Refunds cannot be rolled back.”;
  • a warning for any action that can’t be rolled back, such as refunds and payments: “This action cannot be rolled back. Refunds and payments are final once executed.”;
  • Input (redacted) and an optional Note;
  • Reject or Approve and run.

Approve and run executes the ability immediately, once, as the original agent and WordPress user. The result is recorded in the audit log, and a snapshot is taken first where rollback supports it.

The Approve or reject link opens a single page made for a phone. It shows the agent, the action, the risk, why it needs approval, when it was requested and when it expires, what will change, and a warning when the action can’t be rolled back.

Add an optional Note, then press Approve and run or Reject. The page then shows the outcome, for example “Approved. The action ran.”

  • You must be logged in to WordPress as someone who can approve. If you aren’t, WordPress asks you to log in first and then brings you back to the page.
  • Opening the link decides nothing. Email security scanners often open links automatically, so a decision is only made when a logged-in approver presses a button.
  • The same safety rules apply as in the queue.
  • Only users with the approve capability (administrators) can decide. Shop managers can’t, even with access to Raqvio Agent Guardrails.
  • No self-approval: a request made with your own account must be approved by a different administrator (“This request was made with your own account, so it must be approved by a different administrator.”).
  • Requests can’t be approved while the kill switch is on, or once they have expired or been decided.
  • The approved action runs through a single-use token valid for 5 minutes, bound to exactly the approved input. A paused agent is still blocked.
  • The input of a pending request is encrypted in the database.

Requests expire after 24 hours by default (Settings → Approval requests expire after (hours), 1–336). An hourly job marks expired requests, and marks as failed any approved request that did not finish within 15 minutes.

The call returns raqvio_ag_approval_required with HTTP status 202: “This action needs human approval. It has been queued as approval_id N; poll raqvio-ag/get-approval-status with that approval_id.” The id is also in the error data (approval_id).

The agent can then call raqvio-ag/get-approval-status with { "approval_id": N } to get pending, approved, executed (with the result), rejected, expired or failed. Only the identity that made the request can see it.