What is reviewed
Review applies to actions across boundaries such as:- connected-app writes
- MCP calls
- schedules and persistent automation
- sandbox commands and processes
- public sharing
- skill installation or removal
- agent-to-agent messaging and delegation
- external network access
- knowledge writes
Decision lifecycle
The reviewer considers user intent, authorization, effect, and risk. Sensitive arguments are redacted and bounded before review or audit storage.What each decision means
Repeated denials in one turn trigger a human decision instead of allowing an agent to keep proposing near-identical actions.
If automatic review is unavailable or cannot preserve the review record, SuperEmber fails closed to human approval.
Delegated work has stricter authorization
A delegation is authored by another agent, not directly by a human. It does not grant explicit authorization for destructive changes, permission changes, financial or legal commitments, credential access, or other high-impact actions. When a delegated agent needs a human decision:- The target team’s Main operation thread changes to Waiting for a human decision.
- A review-needed receipt appears in that operation thread.
- The source conversation receives a waiting receipt and a link when available.
- After approval or denial, both receipts update in place.
- Approval resumes the parked call; denial tells the agent to choose a safer route or report the blocker.
Approval is exact and one-use
Before approving, verify:- the tool and operation
- the account, recipient, or target system
- the arguments and scope
- the expected external effect
- that the action still matches the user’s request