Tutorials
Quick: gate a write with approval
Put a human gate on the highest-consequence node.
Short recipe — one approval, correctly placed. Approvals live on nodes, not in a separate app.
Steps
- Open the workflow containing the external write (destination or ontology write node).
- Select the writing node and open its policy block.
- Require approval at node level — the gate sits as close to the effect as possible. Workflow-level approval covers launches; node-level covers consequences.
- Check the aggregated permissions view: the gate shows on the node and rolls up to the graph summary.
- Dry-run to confirm the gate triggers: the preview should state that approval is required before the write executes.
- Commit the policy change as a version, then approve the first gated run deliberately — reading the evidence the approval presents. The approval record (who, what, why) stays with the run: future audits start there, not in chat logs.
Image: permissions view with the node-level gate highlighted and the pending approval state.
Done means no external write in this workflow executes without a named human decision. Policy fields in Workflow nodes; write rules in Write policies.