4.0Approve
Review sensitive actions before they run
Compare the current record with the proposed change, then release or hold it. The server records the decision with your name and timestamp on every plan.
Now
- order ORD-4471
- buyer d.harper
- value £42.60
- status fulfilled
- courier Evri, delivered Tue
- claim none
- refund none
- buyer_reply none
- stock unchanged
- owner unassigned
- record none
If you release it
- order ORD-4471
- buyer d.harper
- value £42.60
- status exception
- courier Evri, postcode mismatch
- claim CLM-88104, opened 14:02
- refund £42.60 ← waiting on you
- buyer_reply drafted by Mira, not sent
- stock unchanged
- owner you
- record released_by · released_at
Whatever you pick is written on the order: what was asked, who decided, when.
Press either one. Release applies the change and signs it; Hold applies nothing.
Audited on 2026-08-21: no part of the gate lives in client JavaScript. Disabling scripts in the browser bypasses nothing, because the browser is not what is holding the action.
The gate
Not a setting. The shape of the thing.
Rather than one autonomy slider for the whole workspace, each agent carries its own spending ceiling, starting at nothing. What sits above that ceiling is written down and waits for a person, on every plan including the free one.
- 4.1What stopsSpend, refunds, supplier commitments, price changes, cancellations and anything that leaves the workspace under your name.
- 4.2On every planThe gate is not a tier. A shop on the free plan gets the same hold on the same actions as a shop on the largest one.
- 4.3Enforced on the serverThe hold lives in the backend, not in the page. Disabling JavaScript, calling the API directly or driving the product from your own code does not get past it.
Deciding
See the change, not a description of it
An approval that shows you a sentence about what will happen is asking you to trust the summary. Hawi shows the record as it is and as it would be, side by side, with the figures that moved highlighted — so the thing you are approving is the thing you looked at.
- 4.4Before and afterThe order, the listing or the reply in both states. No summary standing in for the actual change.
- 4.5Why it was proposedWhat the agent read and what it concluded, attached to the proposal. You can disagree with the reasoning and not only the outcome.
- 4.6Amend, not just approveYou can change the figure and release the amended version. The choice is not limited to yes and no.
- 4.7AnywhereApprovals reach you on the dashboard, by mail and on your phone. A gate you can only clear at a desk is a gate that gets left open.
The record
Evidence later, not a notification you dismissed
What was asked, who released it, when, and what it looked like at the time stays on the record permanently. When a supplier disputes a figure or an auditor asks who authorised something, the answer is on the order rather than in somebody's memory.
- 4.8Named, not anonymousApprovals carry the person, not just the workspace. 'Someone approved it' is not a state the system can be in.
- 4.9PermanentA released approval is not editable afterwards. Corrections are new records that reference the old one.
- 4.10Automatic settlementLetting an agent settle small amounts unattended is a separate permission with its own switch and its own ceiling, acknowledged explicitly.
The rest of the system
- 1.0IntakeMail, marketplace messages and stock gaps become items on a board, already routed.
- 2.0WatchCover counted against what is selling, so a line that runs out is flagged early.
- 3.0ActNamed agents work the item and hand it between themselves with the evidence attached.
- 5.0MonitorWhat moved, what is stuck, and what is waiting on you — with the numbers behind it.
- 8.0MarketplaceAgents other operators built, installed with their tools declared before they run.
- 9.0LimitsA ceiling on what runs unattended, and the actions no ceiling ever covers.
- 10.0BoardsOne board held by people and agents alike, where the column follows the owner.
- 11.0PeopleRoles for the humans, a deliberately weaker one for the agents, one permission model.
- 12.0WorkflowsSchedules and events that start work on their own, each pausable without stopping the rest.
Start with one agent and one job.