Smart Shikka Tool Approval Workflow Preview

dry_run preview_only approvals_not_persisted execution_off send_off write_off payment_off

Central Confirmation Layer for Future Tools

This is the Tool Approval Workflow Preview — the central confirmation and approval layer for all risky tool actions in Smart Shikka Core. Before any send, write, payment, external API call, research execution, or customer mutation, the owner must approve the action through this workflow. This page is preview-only; no approvals are persisted, no execution is unlocked.

Approval Matrix (12 categories)

CategoryRisk LevelOwner ApprovalPreview Status
Read-Only Preview safe_preview recommended allowed
External API Validation medium_external_lookup required allowed
Email Confirmation medium_external_lookup required allowed
Phone Confirmation medium_external_lookup required allowed
Notification Send high_send_or_write required blocked
Messaging Send high_send_or_write required blocked
File Upload high_send_or_write required blocked
Screenshot Capture high_send_or_write required blocked
PDF Generation high_send_or_write required blocked
Research Live Run high_send_or_write required blocked
Database Write high_send_or_write required blocked
Payment / Invoice Mutation critical_payment_or_customer_mutation required blocked

Risk Levels

LevelRequires Approval
safe_preview No
low_read_only Yes
medium_external_lookup Yes
high_send_or_write Yes
critical_payment_or_customer_mutation Yes

Confirmation Request Preview

Email validation live provider call

Risk: medium_external_lookup · Owner approval required before deliverability check

Phone OTP send

Risk: high_send_or_write · Blocked in preview · Owner approval required

WhatsApp reply send

Risk: high_send_or_write · Blocked in preview · Owner approval required

Research live run

Risk: high_send_or_write · Blocked in preview · Python/network disabled

Payment / invoice mutation

Risk: critical_payment_or_customer_mutation · Blocked in preview · Critical approval required

Owner Decision Preview

Static statuses only — no real decision is persisted or executed.

approve_preview deny_preview request_changes_preview

Blocked Actions

ActionReason
Payment without approvalCritical approval required
Send without approvalOwner must approve before any send
Python research without approvalPython/network disabled in preview
External API without provider/keyProvider selection and key required

Safety Panel

PolicyStatus
Approval persistenceDisabled
Execution unlockDisabled
Send capabilityDisabled
Write capabilityDisabled
Secret exposureNone

Future Unlock Plan

  1. Real approval storage with signed receipts
  2. Signed approval receipt with tamper detection
  3. Audit log integration for all approval decisions
  4. Rate limit enforcement per tool/category
  5. Role-based permissions for approval authority
  6. Live adapter execution only after approved receipt

Approved actions are planned through the Safe Tool Execution Plan. Approved actions still require adapter allowlist before live execution via the Tool Adapter Registry. Live provider calls are routed through External Service Toolkit. Policy Decision API decides when owner approval is required.

Version 2.1.2.0.263 · Phase: tool_approval_workflow_preview · PR: #263 · Smart Shikka