October 14The Operator’s HourSave a seat →

A human decision at the moment it matters

Human oversight.
Autonomous agents.

Give your agents room to work and a clear point to bring you in. Review the deployment, the purchase, or the message to a customer before that step proceeds.

Free for individuals. No card. Your first request executes nothing.

YOUR APPROVAL INBOXWaiting for review

From your coding agent

Ready to deploy.
May I proceed?

The update is ready for your review. This request covers one deployment to production.

Action
Deploy the website update
Destination
Production website
Release
Reviewed revision a1b2c3d
Permission
This exact action, once
Approve onceReject

You review. The agent waits.

Illustrative example · no deployment or approval occurs here.
Your AI toolsYour approval rulesYour decision

Before you give an agent more responsibility

Decide what it can do.
Know when you need a say.

Your team may work across different AI providers. Give each agent its own limits and bring the decisions into one shared history.

Access: what does it need?

Give each agent its own identity and scoped access. Use governed integrations to add credentials without handing the agent your provider keys.

Scope access to the work →

Actions: what may it change?

Define which tools, capabilities, and expenses are allowed. Route actions through an enforcing integration when the limit must be applied before execution.

Set boundaries for new capabilities →

Approval: what needs your review?

Review the exact recipient, message, deployment, or expense. Approve that request once, without changing the standing rules.

Review a message before it leaves →

Oversight: how do you stay in control?

Inspect requests and decisions, track budgets, and revoke access. A decision record shows what was authorized; it does not prove an external action ran.

Keep a shared decision history →

For the people responsible

Keep the work moving.
Keep a say in what happens.

Choose the moments that need a person. Connect the relevant workflow so the agent asks before taking that step.

Deployments01

Before it goes live

Your coding agent is ready to deploy. Review the proposed release and destination before authorizing that step.

Explore this use case →
Purchases & expenses02

Before it spends

An agent needs more API credits or a paid tool. Review the amount and purpose before approving the expense.

Explore this use case →
Outbound messages03

Before it speaks for you

The draft is ready. Review the exact message and recipients before your agent sends or publishes it.

Explore this use case →
Contractor access04

Before access outlives the work

Give a contractor’s agent its own scoped seat, budget, and expiry date. Keep access tied to the assignment.

Explore this use case →
Cross-provider teams05

When the team uses different AI tools

Bring agents from different providers under shared approval rules, with separate agent identities and a shared decision history.

Explore this use case →

Explore all ten use cases →

These workflows require a connected agent or integration. Sanction does not automatically intercept your AI host’s other tools.

One request. One decision.

A clear pause.
A specific yes or no.

Approve the action in front of you without giving the agent blanket permission for whatever comes next.

  1. 01

    The agent brings the details

    What it wants to do, where, and with which inputs. A reason gives you context; the exact request defines what you approve.

  2. 02

    You review and decide

    Approve or reject in the approval inbox, or in Slack when configured. Organizational rules still apply; approval cannot bypass a hard denial.

  3. 03

    It resumes that exact action

    The agent redeems an expiring, one-use permission before proceeding. A changed request, expired permission, or rejection means stop.

One production change, from request to permission
  1. 01 · ProposedDeploy this revision

    The release and destination are specified.

  2. 02 · WaitingPause for review

    The agent requests a human decision.

  3. 03 · ReviewedYou decide

    Review the exact action and approve or reject it.

  4. 04 · If approvedOne-use permission

    Redeem before expiry. A different action needs a new decision.

Illustrative workflow. Approval records permission; it does not prove the deployment ran.

Start with a harmless request. The connection guide walks you through a synthetic approval that executes nothing.

Try one approval →

For agents working autonomously

More independence.
Clear limits.

Give an agent a way to ask for what it needs, respect a refusal, and continue with permission tied to its own identity.

Explore the agent wallet →

Pause at a budget boundary

Escalate an expense above the review threshold. Hard budget limits still deny it; a human approval does not raise them.

Request a new capability

Ask before acquiring a skill, plugin, or integration. Authorization does not install it.

Resume the reviewed action

Redeem a one-use grant for the identical request. Changed arguments require a new decision.

Keep provider keys out of the agent

Route supported calls through the broker or model gateway, which adds vaulted credentials on the server.

Collaborate under its own identity

Give each agent its own key, scope, and budget so authorization stays attributable across tools.

Fits the way you work

Your providers stay yours.

Start with a cooperative approval connection. Add enforcement in the paths you control as your workflow grows.

Govern the execution path

Route tool calls through the MCP broker, check actions in your application integration, or route model usage through the budget gateway. Enforcement covers those connected paths.

Explore the platform →

Keep a decision record

See which agent requested an action and how it was authorized. The record evidences the decision; it does not prove an external action ran.

Read the documentation →

Start with one approval

If you’re not sure, Sanction it.

One safe request. A human decision. A clear next step.