Human approval
Require user approval for tools that modify data or systems. With confirmation on, the gateway pauses each call to the tool and asks the user to approve it. The call reaches the MCP server only after the user clicks Approve.
Who approves
The approval comes from the person who made the call, in their own AI app. It is a confirmation step that slows down risky actions and records a justification. It is not an independent approval:
- No administrator, manager or second person reviews the call, and there is no approval queue or delegation.
- A message such as "An administrator requires confirmation for this tool" means an administrator turned the rule on, not that an administrator approves each call.
- Treat the Approve in Quilr link like the conversation it came from and do not share it.
For separation of duties, restrict the tool instead: disable it with Tool visibility, or limit who can reach it with Group and user rules and Server access.
Configure it on the server
Each tool has two switches.
- Turning Require confirmation on also turns Require justification on. Turn justification off per tool if approval without a written reason is sufficient.
- Require justification needs confirmation on first.
- The confirmation switches are locked while a tool is disabled.
Click Save settings to apply. Good candidates are tools in the Write tools and Destructive tools groups, such as sending messages, deleting records or merging code.
Different rules for groups and users
Confirmation can differ by smart group or user. In Group and user rules, click Add rule, choose A smart group or A single user, and under Tool overrides set Confirmation and Justification for each tool.
Setting Confirmation to On also sets Justification to On. If a user is in several groups with rules, a group that requires confirmation takes precedence; a rule for that single user applies last. Use Effective settings preview to check one user's effective settings.
What your users see
The approval request appears in the user's AI app. What it looks like depends on the client.
ChatGPT and claude.ai also show the Approve in Quilr link under the card, in case the card doesn't load. Both resolve the same request.
Justification
The justification box reads Justification (required to approve) when the tool requires one and Justification (optional) otherwise. Up to 1,000 characters. Approve without a required justification shows A justification is required to approve. and nothing runs. The justification is saved with the call and is never sent to the MCP server or the model.
Deny, dismiss or no answer
A request that was already approved or denied elsewhere shows Already decided.
Review confirmed calls
Open Overall analytics > Activity > Tool calls, or Inspect > Logs on the server card, and click a call. The Tool call detail drawer shows the arguments and the result. The approval decision and the justification are recorded in the call's Metadata.
Going further with the Policy Engine
When the Policy Engine is on for the MCP Gateway, the Human Approval card (stage 3, Request) in Govern > Policy Engine > MCP Gateway decides which calls need approval, and the switches in Tools are read-only. Edit anyway saves values that apply only if the Policy Engine is disabled (see What happens to classic settings). Its tool confirmation effect takes required, which asks for approval with an optional justification, or required_with_justification, which also makes the justification mandatory.
Scenarios the card supports that per-tool switches cannot:
- Approve by tool type, on every server. Match tool tags (for example
write) or thedestructiveannotation, so new tools that fit the pattern need approval as soon as they appear. - Approve for some people or agents only. Combine the tool condition with smart groups, user email or agent name, for example require approval from contractors but not from the team that owns the server.
- Approve on one route. Require approval only on direct connections or only through OneMCP, using route kind.
runs on requestpriority 700
Edits join a shared draft and apply once you publish a revision.
Related
- Tool visibility - enable and disable tools.
- Security guardrails - block or redact sensitive data in calls.
- Policy Engine overview - how cards, stages and priorities work.