Skip to main content

Human approval

Require user approval for tools that modify data or systems. With confirmation on, the gateway pauses each call to the tool and asks the user to approve it. The call reaches the MCP server only after the user clicks Approve.

Who approves​

The approval comes from the person who made the call, in their own AI app. It is a confirmation step that slows down risky actions and records a justification. It is not an independent approval:

  • No administrator, manager or second person reviews the call, and there is no approval queue or delegation.
  • A message such as "An administrator requires confirmation for this tool" means an administrator turned the rule on, not that an administrator approves each call.
  • Treat the Approve in Quilr link like the conversation it came from and do not share it.

For separation of duties, restrict the tool instead: disable it with Tool visibility, or limit who can reach it with Group and user rules and Server access.

Configure it on the server​

Go toQuilrAI consoleSettingsAI GatewayMCP Gatewayserver cardConfigureTools

Each tool has two switches.

SwitchWhat it does
Require confirmationThe user must approve each call before the gateway forwards it.
Require justificationThe user must type a justification to approve. Denying a call does not require one.
  • Turning Require confirmation on also turns Require justification on. Turn justification off per tool if approval without a written reason is sufficient.
  • Require justification needs confirmation on first.
  • The confirmation switches are locked while a tool is disabled.

Click Save settings to apply. Good candidates are tools in the Write tools and Destructive tools groups, such as sending messages, deleting records or merging code.

Different rules for groups and users​

Confirmation can differ by smart group or user. In Group and user rules, click Add rule, choose A smart group or A single user, and under Tool overrides set Confirmation and Justification for each tool.

ValueMeaning
InheritUse the server's setting from Tools.
OnRequire it for this group or user.
OffDon't require it for this group or user.

Setting Confirmation to On also sets Justification to On. If a user is in several groups with rules, a group that requires confirmation takes precedence; a rule for that single user applies last. Use Effective settings preview to check one user's effective settings.

What your users see​

The approval request appears in the user's AI app. What it looks like depends on the client.

ClientWhat the user sees
VS CodeA native form in the chat: the tool name and server, the arguments, a Run this tool? choice of Approve or Deny, and a justification box.
ChatGPT and claude.aiAn Approval required card in the conversation showing the server, the tool and its arguments, a Justification box, and Approve and Deny buttons. Approve runs the call once and the card shows the result.
Other clientsThe assistant replies with an Approve in Quilr link. It opens an Approval required page showing the server, the tool, the arguments and Why approval is needed, with a Justification box and Approve and Deny buttons. After approving, the user asks the assistant to run the call again.

ChatGPT and claude.ai also show the Approve in Quilr link under the card, in case the card doesn't load. Both resolve the same request.

Justification​

The justification box reads Justification (required to approve) when the tool requires one and Justification (optional) otherwise. Up to 1,000 characters. Approve without a required justification shows A justification is required to approve. and nothing runs. The justification is saved with the call and is never sent to the MCP server or the model.

Deny, dismiss or no answer​

What happensResult
User clicks DenyThe call never runs. The assistant is told the user declined.
User closes the form or cardThe call never runs.
Nobody answers in timeThe request expires after 10 minutes and the call never runs. The card or page says the request expired and asks the user to try again.

A request that was already approved or denied elsewhere shows Already decided.

Review confirmed calls​

Open Overall analytics > Activity > Tool calls, or Inspect > Logs on the server card, and click a call. The Tool call detail drawer shows the arguments and the result. The approval decision and the justification are recorded in the call's Metadata.

Going further with the Policy Engine​

When the Policy Engine is on for the MCP Gateway, the Human Approval card (stage 3, Request) in Govern > Policy Engine > MCP Gateway decides which calls need approval, and the switches in Tools are read-only. Edit anyway saves values that apply only if the Policy Engine is disabled (see What happens to classic settings). Its tool confirmation effect takes required, which asks for approval with an optional justification, or required_with_justification, which also makes the justification mandatory.

Scenarios the card supports that per-tool switches cannot:

  • Approve by tool type, on every server. Match tool tags (for example write) or the destructive annotation, so new tools that fit the pattern need approval as soon as they appear.
  • Approve for some people or agents only. Combine the tool condition with smart groups, user email or agent name, for example require approval from contractors but not from the team that owns the server.
  • Approve on one route. Require approval only on direct connections or only through OneMCP, using route kind.
confirm_write_toolsrequest

runs on requestpriority 700

WhenTool tagshas entrywrite
Then
tool confirmationrequired

Edits join a shared draft and apply once you publish a revision.