Autonomy that stops and asks. When policy holds an action, it lands in one queue with the reason attached, waits for a human — or their delegate — and releases exactly once. The decision, the decider and what executed become part of the same audit trail as the run itself.
When an agent acts autonomously, the organization owns the outcome. When a human approves the action, a named person owns it — with the policy, the payload and the timestamp on record. That chain is what lets an enterprise say yes to autonomy at all.
So the queue is built like a control, not a chore: explained holds, grouped decisions, covered absences, hard expiry, and a record that writes itself. The gate is exactly as wide as your policy says, and never wider.
Six properties that make human-in-the-loop workable at enterprise volume — without softening the gate.
There are two different questions a human can be asked, and the platform keeps them apart. The autonomy floor asks: may this worker pursue this plan at all? The compliance floor asks, later and independently: may this specific tool call execute? Approving a plan never silently approves its writes — a policy-held action still stops and asks, even inside an approved plan.
Every grant is consumed by the first matching call. Approve an email send and exactly one email sends; the next send creates a fresh request. Grants are scoped to the workspace, the worker and the tool, and expire on their own in 24 hours if unused. There is no 'approved forever' state quietly accumulating in the background.

Everything waiting on a human sits in one queue, not scattered across email threads. Each item carries the policy that held it — the rule, in plain language — the sanitized payload, and how long it has waited. Identical asks group into one card so a batch of fifty matching requests is one decision, not fifty. Aging is visible at a glance and escalates before it becomes a problem.

An approver going on leave delegates their authority for a window — one active delegation per person, org-scoped, revocable at any time. The delegate sees and decides the delegator's queue, and every decision made this way is stamped 'decided on behalf of' in the audit trail. Work doesn't pile up behind an empty chair, and accountability never blurs.

A held action is only as good as the human's ability to reach it. The queue is on the web app, the mobile app, the desktop app and the browser extension, with the same policy context everywhere. Critical holds — a circuit breaker halt, a hard budget cap — push through quiet hours; routine ones respect them. A run blocked at 6pm doesn't wait for a laptop to open at 9.

Who approved what, when, under which policy, on whose behalf, and what executed as a result — all of it lands in the same audit trail as the runs themselves, pinned to the config version in force at the time. When someone asks 'who authorized this?', the answer is a row, not a reconstruction.
