| Time | Status | Name | Kind | Agent | Chain | Duration | Rule |
|---|
Each person and each AI agent gets its own key. People can open this dashboard; approvers can approve
held actions; admins manage the team and settings. Agents can only ask permission and report what they did.
Roles such as finance let rules require a specific team to approve.
Setting this up for a team? Tell us about your team and we'll help with rules, approvers and rolling it out, or book 15 minutes with the founder.
| Name | Type | Access | Roles | Added |
|---|
| Approver | Approved | Rejected |
|---|
| Agent | Actions | Blocked | Held | Approved | Rejected | Failed | Last seen |
|---|
| Rule | Why | Times |
|---|
| Tool | Calls |
|---|
| When | Who | What | Details |
|---|
When an agent needs approval, the gateway can ping you on your phone and in Slack. Each message has a secure one-tap link to approve or reject that one action; the link stops working once it's decided.
Agents copy what they read: a ticket's customer ends up in a pull request description or a public issue. When an agent puts text where others can read it (a PR, an issue or comment, a gist, a chat post) and it names a customer on this list, it waits for a person. Card numbers, social security numbers, IBANs and lists of people's emails or phone numbers are held there too, with no list needed.
ChatGPT and claude.ai connectors, Devin, n8n and other cloud agents use MCP servers by URL. Add the app's MCP server here and give the agent its Squidbrake URL instead: every call is checked like any other and recorded as the agent that made it.
| Name | URL for your agents | The app's server | Status |
|---|
The agent signs in with one of its keys (Team, add an AI agent): Authorization: Bearer gw_….
If the app only takes a URL, add ?key=gw_… to it, and treat that URL like a password.
What agents may do is decided by rules.yaml on the gateway: allow, block, or hold for a person
(optionally a specific role). Edits apply within seconds. Use Test a rule to check what would happen.