Deterministic State Machine & Authorization

Human-in-the-Loop (HITL) Governance

Empower autonomous agent execution without surrendering operational control. CadreGPT enforces deterministic approval gates before high-risk mutations touch your database, external APIs, or customer records.

How the HITL Interception Cycle Works

Deterministic state machine boundaries prevent unverified actions from executing in production.

1

Autonomous Proposal

The agent reasons over the goal and drafts a tool action (e.g., executing a SQL mutation or dispatching a refund).

2

Policy Interception

Pre-execution guardrails detect high-privilege tool tags and immediately transition the task into AWAITING_APPROVAL.

3

Omnichannel Dispatch

Real-time SSE triggers the in-app drawer while transactional emails notify designated workspace approvers with context diffs.

4

Verifiable Sign-off

Operator inspects parameter payloads, approves with optional modifications, or rejects with guidance for agent self-correction.

Granular Tool Permissions

Classify tools as Autonomous (read-only research, calculations) or Governed (write, update, delete, payments). Never block routine work while keeping critical boundaries locked.

Configurable Expiration Windows

Avoid orphaned processes. If an approval request is not acted upon within the configured window (e.g., 24 hours), the task safely terminates and unlocks reserved credits.

SOC 2 Compliance Audit Trails

Every human authorization event creates a tamper-proof receipt documenting approver email, IP address, timestamp, parameter delta, and final tool response.

Knowledge Base & FAQs

Frequently Asked Questions: Human-in-the-Loop Governance

Everything you need to know about setting up authorization policies, real-time drawers, and fail-safe controls.

01.What triggers a Human-in-the-Loop approval gate?

Approval gates trigger whenever an agent attempts to execute an action tagged with high privilege or state mutation—such as issuing database updates, triggering external payments, modifying code repositories, dispatching public webhooks, or deleting persistent records. Read-only intelligence and planning actions proceed autonomously without interruption.

02.How are reviewers alerted when an agent requests authorization?

Approvers receive multi-channel notifications in real time. Active operators in the CadreGPT dashboard receive instantaneous Server-Sent Events (SSE) updates opening the sliding Approval Drawer. Offline approvers receive authenticated transactional emails via Resend containing the full task context, parameter diffs, and secure one-click review links.

03.Can an agent bypass approval if no reviewer responds?

Never. Invariance is strictly enforced by the task state machine. If an approval is pending, the agent’s execution lock remains suspended in AWAITING_APPROVAL. After a configurable expiration safety window (default 24 hours), the task safely terminates into an EXPIRED or CANCELLED status, preventing unattended mutations.

04.Can reviewers modify parameters before approving execution?

Yes. Reviewers can inspect the exact payload, SQL query, or API parameters proposed by the agent. If slight adjustments are needed, approvers can tweak argument values directly in the Approval Drawer before granting execution authorization, or reject the turn with written feedback that the agent uses to self-correct.

05.Is the human approval decision auditable for SOC 2 compliance?

Every approval, rejection, parameter override, and timeout is permanently recorded in the immutable audit ledger. Entries record the exact user ID, IP address, timestamp, pre-execution diff, and cryptographic hash, providing an airtight chain of custody for enterprise governance.

Ready to Deploy Safe, Governed Agents?

Experience real-time approval gates and state transitions in our interactive sandbox workspace.

Start Free Sandbox Trial ($1.00 Included) →