Skip to content

Capability · Approval gate

Propose → approve → dispatch. Default-deny.

Default-deny control: mutation-capable tool calls become pending proposals and wait for your decision before anything is dispatched.

Proposal · send renewal quotedrafted in the workspacecredentials by {{secret}} onlyabove your threshold → askwaiting…Approveactivity logdispatched
In the productMailCalendarCatalog

monopea never lets an agent act outward on its own say-so. Every mutation-capable tool call — send the email, update the record, move the money — is drafted as a proposal: the exact tool, the exact arguments, held in a pending state while the run blocks and waits for your decision.

That is the whole architecture in one sentence: propose → approve → dispatch. The agent plans and drafts at machine speed; outward execution happens only after a human decision — or under a policy you granted explicitly, on the record, in advance.

The Monopea chat, showing an answer whose figures each carry a citation to the board update it read, and beneath it a standing objective the agent has drafted as a proposal — its exact arguments in view, waiting on Reject or Approve, with the header set to approve nothing on its own.
Chats · the drafted call, its arguments open, waiting on Reject or Approve
  1. 01 / MECHANISM

    How the propose → approve → dispatch lifecycle works

    When the agent decides an action is needed, it does not execute the call. It writes a proposal — tool name, full arguments, context — and the run enters a blocked state until you approve or reject it. Only an approved proposal is dispatched, and every step of that lifecycle is logged.

    You see exactly what would run before it runs. Approve, and the call dispatches immediately; reject, and the agent takes the feedback and re-plans. There is no third path where an ungated action slips through: a call either matches a policy you granted or it waits for you.

    • The agent drafts the exact call — tool and arguments — before anything runs
    • The run blocks until you decide; approval is what dispatches the call
    • Rejections feed back into the plan instead of failing silently
  2. 02 / MECHANISM

    Why default-deny is the right default

    Most agent frameworks execute tools by default and rely on prompt instructions to behave. monopea inverts that: dispatch is denied unless a decision or an explicit policy allows it. A tool the platform has never evaluated fails closed — its calls route to review automatically, because unknown should never mean allowed.

    The gate lives in the runtime, not the prompt. A system-prompt instruction can be argued out of by a clever input; an architectural gate cannot. Whatever model you run — Claude, GPT, or a Swiss-hosted open-weight model — the same gate sits between it and your tools.

  3. 03 / MECHANISM

    Raise autonomy deliberately, one threshold at a time

    Default-deny does not mean approving everything forever. Every tool carries a risk level — NONE, LOW, MEDIUM, HIGH, CRITICAL — and you set the highest level allowed to run unattended. Calls at or below the line dispatch without a pause; everything above it still waits for you. You set that line for the workspace, and you can set a different one for a single project.

    In practice, autonomy expands at the pace of your confidence. Week one the line sits at NONE and everything stops for review. By week four the routine, low-risk plays flow while anything novel or sensitive still waits. Moving the line is itself recorded — who moved it, from what to what — so the agent gets faster without your exposure growing silently.

    • One risk threshold, set per workspace and overridable per project
    • Every change is recorded with who made it and how far it moved
    • Sensitive and unknown actions keep stopping for you
  4. 04 / MECHANISM

    Built for EU AI Act Article 14 oversight

    Article 14 of the EU AI Act, enforceable since August 2026, requires effective human oversight of high-risk AI systems — oversight implemented as a real control, not a suggestion in a prompt. monopea’s proposal gate is exactly that kind of control: external to the model, enforced by the runtime, and evidenced in logs.

    Every proposal, approval, rejection, and dispatch is written to the audit trail, and audit-chain checkpoints are Ed25519-signed so the record is tamper-evident. monopea was built for this oversight model — that is an architectural fit, not a certification claim.

The Members surface, showing what each role may do — owner, responder and viewer — beside a roster where every person carries the role that decides whether they can approve the agent’s outward actions.
Members · the roles that decide who may approve an outward action

Why it matters

What it changes in practice.

01

No surprise actions

Outward actions are drafted and held, not fired. You see the exact call before it exists in the world.

02

Autonomy on your terms

Raise the risk threshold for the plays you trust; everything else keeps stopping for you.

03

Unknowns fail closed

A tool the platform has not evaluated routes to review by default. Unknown never means allowed.

04

Evidence, not assurances

The full decision history is logged and Ed25519-signed, so oversight is provable after the fact.

FAQ

Approval gate, in short.

What happens when the agent wants to do something risky?
The action becomes a pending proposal — exact tool and arguments — and the run blocks until you approve or reject it. Nothing is dispatched while it waits. Reject it and the agent re-plans with your feedback instead of pushing through.
Does every single action require my approval?
No — that would make autonomy pointless. Mutation-capable calls are held by default, but you can raise the autonomy threshold so trusted, low-risk actions dispatch without a pause. Every change to it is explicit, recorded, and reversible.
What happens with a tool Monopea has never seen?
It fails closed. Calls from unknown or unevaluated tools are routed to review automatically rather than dispatched — default-deny applies most strictly exactly where knowledge is thinnest.
Is this EU AI Act Article 14 compliant?
Monopea’s gate was built for the oversight Article 14 describes: a human control external to the model, enforced by the runtime, with a signed audit trail as evidence. That is an architectural fit, not a certification — no formal certification has been obtained.
Is the approval history verifiable?
Yes. Every proposal, decision, and dispatch is logged, and audit-chain checkpoints are Ed25519-signed, so the history is tamper-evident rather than just a database row.

Start with everything gated. Open it up as you go.

Open a workspace, give the agent a task, and approve what it proposes. Stored in Switzerland, processed in the EU.