Approvals, safety, and evidence
Codelit separates proposing an action from executing it. A write approval is bound to the user, run, tool, operation, and expiry so it cannot be reused for different work.
Put approval at the risk boundary
Require approval immediately before publishing, sending, merging, deleting, purchasing, or changing access. Read-only gathering usually does not need an approval unless the source is unusually sensitive.
Read the review
The global bell groups waiting work by urgency, workspace, Agent App or automation, and run. Open one review to see the exact gated step, risk, deadline, original proposal digest, and only the action fields that the workflow bound for review.
- Edit only the server-declared fields; unreviewed fields and type changes fail closed.
- Approve and resume stores the original proposal, reviewed diff, signed-in reviewer, and final digest atomically with the checkpoint.
- Hold for later keeps the exact unchanged preview pending. Edit step closes it and focuses the matching Flow card; Deny records a terminal no-action receipt. Expired requests halt instead of inheriting a late decision.
Use receipts as evidence
The execution terminal and run receipt record step status, bounded outputs, tool attempts, approvals, cost estimates, and evidence links. Receipts are for review and replay; they are not a promise that an external system stayed unchanged afterward.