[{"data":1,"prerenderedAt":2361},["ShallowReactive",2],{"docs-nav":3,"docs-article-engineering\u002Fsystem-design\u002Fagentic-platform\u002Fproducts\u002Fhuman-review":797},[4,17,27,44,55,67,75,82,94,106,114,122,129,135,144,153,161,169,177,189,202,211,218,229,240,248,260,268,276,286,296,305,314,323,331,337,343,350,356,364,371,378,383,393,401,410,415,422,432,439,444,451,458,462,467,475,487,499,509,516,525,533,539,545,551,557,563,567,579,593,603,614,621,626,633,640,646,653,658,665,673,678,686,692,699,704,710,721,730,740,747,753,761,767,776,782,791],{"path":5,"title":6,"description":7,"group":8,"section":6,"order":9,"tags":10,"lastUpdated":16},"\u002Fagents\u002Fagentic-crm","Agentic CRM","Research brief and build plan for an AgencyCore agentic CRM layer, rendered as an interactive page — the core operating loop, the target architecture, the typed-tool risk gateway, the proposed-actions review queue, and the four-slice MVP.","Agents",0,[11,12,13,14,15],"crm","agents","ai","architecture","research","2026-06-12",{"path":18,"title":19,"description":20,"group":8,"section":21,"order":22,"tags":23,"lastUpdated":26},"\u002Fagents\u002Fchat","Chat agent","High-level system design of the AgencyCore chat agent — core components, data flow, and the two abstractions that hold it together.","Reference",1,[12,14,24,25],"chat","system-design","2026-05-13",{"path":28,"title":29,"description":30,"group":8,"section":31,"order":32,"tags":33,"lastUpdated":43},"\u002Fagents\u002Fcompany-enrichment","Company Enrichment","The company enrichment workflow - a cache-first read in front of the company intelligence database that fills firmographic, contact and technographic facts via a fixed-order provider waterfall, and writes every resolved fact back with provenance so the first org pays once and every later search rides free.","Enrichment",2,[12,34,35,36,37,38,39,40,41,42],"workflow","enrichment","companies","waterfall","cache","intelligence-database","firmographics","provenance","sonar","2026-06-10",{"path":45,"title":46,"description":47,"group":8,"section":48,"order":9,"tags":49,"lastUpdated":54},"\u002Fagents\u002Fcompany-sonar","Company Signals","Signal-first company discovery for marketing agencies, on the Claude Agent SDK, with a global intelligence cache and deterministic composite scoring.","Company Sonar",[12,34,42,50,51,52,35,53,14],"company-search","signals","agent-sdk","scoring","2026-06-08",{"path":56,"title":57,"description":58,"group":8,"section":48,"order":22,"tags":59,"lastUpdated":66},"\u002Fagents\u002Fcompany-sonar\u002Fsignal-monitoring","Company Signals Monitoring","Realtime signal capture layer on top of the data graph. Detects hot events, scores them with a Claude managed agent against each agency's ICP, fans out alerts.",[14,51,60,61,62,63,64,65],"intel","icp","alerts","monitoring","sse","managed-agents","2026-06-09",{"path":68,"title":69,"description":70,"group":8,"section":71,"order":22,"tags":72,"lastUpdated":74},"\u002Fagents\u002Fconcepts\u002Fchat-agent-design-principles","Designing chat agents","The 2026 playbook for production chat agents that reach into internal systems via tools — context engineering, memory, tool design, when to add complexity.","Concepts",[12,14,24,73],"context-engineering","2026-05-14",{"path":76,"title":77,"description":78,"group":8,"section":71,"order":32,"tags":79,"lastUpdated":74},"\u002Fagents\u002Fconcepts\u002Fsystem-prompt-architecture","System prompt architecture","How to structure a production chat agent system prompt — eight sections, what each one does, and the rules vendors converge on.",[12,80,81],"prompt-engineering","system-prompt",{"path":83,"title":84,"description":85,"group":8,"section":84,"order":9,"tags":86,"lastUpdated":54},"\u002Fagents\u002Fenvoy","Envoy","High-level system design for the AI outreach engine — the sequence step state machine, the human-in-the-loop draft approval gate, multi-source context enrichment, and the inbox sentiment flow, rendered as an interactive page.",[12,87,88,89,90,91,92,93,14],"envoy","outreach","sales-engagement","sequences","state-machine","human-in-the-loop","nylas",{"path":95,"title":96,"description":97,"group":8,"section":98,"order":9,"tags":99,"lastUpdated":16},"\u002Fagents\u002Fheadhunter","Headhunter","The AI talent-search pipeline on one page - the production six-step design with its current-title relevance gate, and the 2.0 system design with internal-first waterfall sourcing, a pluggable source registry, automatic entity resolution, and a people intelligence graph that compounds every run.","General Search",[12,34,100,101,14,25,102,37,103,104,105],"headhunter","recruiting","multi-source","entity-resolution","people-intelligence","flywheel",{"path":107,"title":108,"description":109,"group":8,"section":21,"order":32,"tags":110,"lastUpdated":113},"\u002Fagents\u002Fpaperclip","Paperclip","Architecture deep dive into the Paperclip orchestration system.",[12,14,111,112],"orchestration","paperclip","2026-04-20",{"path":115,"title":116,"description":117,"group":8,"section":31,"order":22,"tags":118,"lastUpdated":16},"\u002Fagents\u002Fpeople-enrichment","People Enrichment","The people enrichment workflow - a cache-first read in front of the people intelligence database that fills profile, contact and employment facts via a fixed-order provider waterfall, keyed on the LinkedIn URL, and writes every resolved fact back with provenance so the first org pays once and every later search rides free. The fill step Headhunter and People Signals both call.",[12,34,35,119,37,38,39,120,41,100,121],"people","linkedin","people-sonar",{"path":123,"title":124,"description":125,"group":8,"section":126,"order":9,"tags":127,"lastUpdated":54},"\u002Fagents\u002Fpeople-sonar","People Signals","Signal-first people discovery for marketing agencies, built on the headhunter pipeline, with a composite score weighted by signal strength, source reputation, recency, and ICP fit.","People Sonar",[12,34,121,128,51,100,35,53,14],"people-search",{"path":130,"title":131,"description":132,"group":8,"section":126,"order":22,"tags":133,"lastUpdated":54},"\u002Fagents\u002Fpeople-sonar\u002Fpeople-signal-monitoring","People Signals Monitoring","Forward-looking design for the push layer that tracks known people - champions, past contacts, target-company decision-makers - and fires a warm lead the moment they change jobs, get promoted, or their company has an event.",[14,51,60,119,63,134],"warm-leads",{"path":136,"title":137,"description":138,"group":139,"section":140,"order":22,"tags":141,"lastUpdated":143},"\u002Fengineering\u002Fguides\u002Fagent-execution-stack","The Agent Execution Stack","Durable workflows over pluggable agent backends — how AgencyCore runs AI agents on Inngest over a webhook-driven Claude Managed Agents backend.","Engineering","Guides",[12,142,14,25],"inngest","2026-06-25",{"path":145,"title":146,"description":147,"group":139,"section":140,"order":9,"tags":148,"lastUpdated":143},"\u002Fengineering\u002Fguides\u002Fagent-runtime","Agent runtime","How AgencyCore runs AI agents on a provider-neutral runtime — the abstraction layer that lets us swap the agent backend, with Claude managed agents as the current provider.",[12,149,14,150,151,152,25],"runtime","anthropic","claude","providers",{"path":154,"title":155,"description":156,"group":139,"section":21,"order":157,"tags":158,"lastUpdated":160},"\u002Fengineering\u002Freference\u002Fagno-to-agent-sdk-migration","Agno → Claude Agent SDK migration","System-design spec for moving the ac-python-api workflow engine off Agno onto Anthropic's Claude Agent SDK \u002F Managed Agents, tiered by control-flow shape.",10,[12,14,159,52,65],"migration","2026-06-06",{"path":162,"title":163,"description":164,"group":139,"section":21,"order":22,"tags":165,"lastUpdated":54},"\u002Fengineering\u002Freference\u002Fcloudflare-agent-sandbox","Cloudflare agent sandbox","Cloudflare's Workers-based agent platform, evaluated as an alternative sandbox for our Agno workflows.",[12,166,167,168,159],"sandbox","cloudflare","workers",{"path":170,"title":171,"description":172,"group":139,"section":21,"order":32,"tags":173,"lastUpdated":176},"\u002Fengineering\u002Freference\u002Fvirtual-filesystem-rag","Virtual filesystem for AI assistants","How ChromaFs provides AI agents with structured file access.",[12,174,14,175],"rag","chromafs","2026-04-18",{"path":178,"title":179,"description":180,"group":139,"section":181,"order":182,"tags":183,"lastUpdated":188},"\u002Fengineering\u002Fsystem-design\u002Fagentic-platform\u002Fcapabilities\u002Fstate-and-knowledge","State and knowledge","What a run may know. One deterministic context builder over application state, knowledge and memory, one owner for every fact, and memory that is written through a tool.","Agentic platform",11,[184,185,186,11,187],"context","memory","knowledge","pgvector","2026-08-31",{"path":190,"title":191,"description":192,"group":139,"section":181,"order":157,"tags":193,"lastUpdated":201},"\u002Fengineering\u002Fsystem-design\u002Fagentic-platform\u002Fcapabilities\u002Ftools-and-integrations","Tools and integrations","A tool is the one way an agent reaches the world. AgencyCore owns the model facing contract, the invoke path, the credentials and the result boundary.",[194,195,196,197,198,199,200],"tools","integrations","mcp","agno","policy","security","idempotency","2026-09-04",{"path":203,"title":204,"description":205,"group":139,"section":181,"order":22,"tags":206,"lastUpdated":210},"\u002Fengineering\u002Fsystem-design\u002Fagentic-platform\u002Fcontract","Platform contract","One platform behind chat, interactive channels, triggers, approvals and background runs, with one Agno runtime, one tool layer, one state layer, and three cross-cutting planes.",[12,14,197,142,194,207,149,208,198,209],"skills","channels","observability","2026-09-02",{"path":212,"title":181,"description":213,"group":139,"section":214,"order":22,"tags":215,"lastUpdated":201},"\u002Fengineering\u002Fsystem-design\u002Fagentic-platform","The whole agentic platform on one page - who starts a run, the one boundary every run passes, how the work executes, and what comes back.","System design",[12,14,216,197,142,217,198],"overview","runs",{"path":219,"title":220,"description":221,"group":139,"section":181,"order":222,"tags":223,"lastUpdated":228},"\u002Fengineering\u002Fsystem-design\u002Fagentic-platform\u002Finterfaces\u002Fagent-access","Agent access (CLI and MCP)","How an outside AI agent reaches AgencyCore. The ac CLI works today as a user seat. An MCP server is planned and not designed.",6,[224,196,12,151,225,226,227],"cli","access","auth","todo","2026-08-18",{"path":230,"title":231,"description":232,"group":139,"section":181,"order":233,"tags":234,"lastUpdated":239},"\u002Fengineering\u002Fsystem-design\u002Fagentic-platform\u002Finterfaces\u002Fchannel-gateway","Channel gateway","The only layer that knows both an interactive channel and the platform. One message shape converges inbound, one intent shape diverges outbound, and no model call happens here.",3,[208,235,236,237,238,199],"slack","web","identity","sessions","2026-08-30",{"path":241,"title":242,"description":243,"group":139,"section":181,"order":244,"tags":245,"lastUpdated":210},"\u002Fengineering\u002Fsystem-design\u002Fagentic-platform\u002Finterfaces\u002Ffront-door","Front door","The conversational control layer. It turns a request into one structured decision, then deterministic application code answers or hands work to RunManager.",4,[246,247,197,184,198,217],"front-door","routing",{"path":249,"title":250,"description":251,"group":139,"section":181,"order":32,"tags":252,"lastUpdated":259},"\u002Fengineering\u002Fsystem-design\u002Fagentic-platform\u002Finterfaces\u002Fsurfaces","Surfaces","Every product surface and its API contract. Web chat goes through the gateway; every schema-native surface calls the domain API.",[253,254,24,255,256,257,258,217,64],"surfaces","api","approvals","prospects","saved-searches","builder","2026-09-03",{"path":261,"title":262,"description":263,"group":139,"section":181,"order":264,"tags":265,"lastUpdated":188},"\u002Fengineering\u002Fsystem-design\u002Fagentic-platform\u002Finterfaces\u002Ftriggers","Triggers","A Run with no person. Every producer emits one Event, matching is deterministic, and dispatch reuses RunManager, Policy and Inngest.",5,[266,267,142,200],"triggers","events",{"path":269,"title":270,"description":271,"group":139,"section":181,"order":272,"tags":273,"lastUpdated":259},"\u002Fengineering\u002Fsystem-design\u002Fagentic-platform\u002Fplanes\u002Fidempotency","Idempotency","One durable PostgreSQL key service prevents duplicate effects and freezes mutable input before selected Run starts. A Run start is guarded by a unique index on the Run row.",14,[200,217,194,274,275],"webhooks","reliability",{"path":277,"title":278,"description":279,"group":139,"section":181,"order":280,"tags":281,"lastUpdated":285},"\u002Fengineering\u002Fsystem-design\u002Fagentic-platform\u002Fplanes\u002Fobservability-and-operations","Observability and operations","One run row, one span tree and one usage meter. Sentry reports system failure; AgencyCore spans explain what the agent did.",13,[209,217,282,283,64,284],"spans","usage","sentry","2026-08-26",{"path":287,"title":288,"description":289,"group":139,"section":181,"order":290,"tags":291,"lastUpdated":295},"\u002Fengineering\u002Fsystem-design\u002Fagentic-platform\u002Fplanes\u002Fpolicy-and-governance","Policy and governance","One deterministic plane answers may this happen, at three checkpoints, with one grant model, one approval model and one decision log.",12,[198,292,255,293,294],"permissions","limits","governance","2026-08-25",{"path":297,"title":6,"description":298,"group":139,"section":299,"order":22,"tags":300,"lastUpdated":210},"\u002Fengineering\u002Fsystem-design\u002Fagentic-platform\u002Fproducts\u002Fagentic-crm","The AgencyCore CRM loop for turning signals and discovery into qualified organization prospects, CRM relationships and outreach.","Agentic products",[11,301,51,302,256,35,303,304,87],"lead-generation","intelligence","signals-search","email-sequence",{"path":306,"title":307,"description":308,"group":139,"section":299,"order":264,"tags":309,"lastUpdated":188},"\u002Fengineering\u002Fsystem-design\u002Fagentic-platform\u002Fproducts\u002Fbuilder-chat","Front door builder chat","Conversational authoring for organization-specific Agent and Workflow definitions, entered through the normal Front Door and backed by the existing DefinitionService.",[310,311,246,12,312,313,198],"authoring","definitions","workflows","templates",{"path":315,"title":316,"description":317,"group":139,"section":181,"order":318,"tags":319,"lastUpdated":201},"\u002Fengineering\u002Fsystem-design\u002Fagentic-platform\u002Fproducts\u002Fcapability-contracts","Company, People and Signals contracts","The five Phase 7 product capabilities, their bounded inputs, stable references, permissions and results.",21,[320,321,119,51,322],"capabilities","company","contracts",{"path":324,"title":325,"description":326,"group":139,"section":181,"order":327,"tags":328,"lastUpdated":330},"\u002Fengineering\u002Fsystem-design\u002Fagentic-platform\u002Fproducts\u002Fcapability-scenarios","Capability design scenarios","Normal, failure and recovery cases for the Phase 7 capability contracts, with implementation owners.",22,[320,329,321,119,51],"validation","2026-09-05",{"path":332,"title":333,"description":334,"group":139,"section":299,"order":233,"tags":335,"lastUpdated":210},"\u002Fengineering\u002Fsystem-design\u002Fagentic-platform\u002Fproducts\u002Femail-sequence","Email sequence workflow","Envoy durable outreach for one or many people, with fresh context, approvals, reply waits, follow-ups and Nylas transport.",[336,87,34,142,93,255],"email",{"path":338,"title":339,"description":340,"group":139,"section":299,"order":244,"tags":341,"lastUpdated":188},"\u002Fengineering\u002Fsystem-design\u002Fagentic-platform\u002Fproducts\u002Fgeneral-chat","Front door general chat","The default conversational answer path for AgencyCore. It answers from supplied context, cites what it used, asks when context is insufficient, and delegates real work through the normal Front Door.",[24,246,186,184,247,342],"citations",{"path":344,"title":345,"description":346,"group":139,"section":299,"order":222,"tags":347,"lastUpdated":188},"\u002Fengineering\u002Fsystem-design\u002Fagentic-platform\u002Fproducts\u002Fhuman-review","Human review inbox","One product page for every agentic action that is paused because a person must authorize an exact proposal. It is a view over the shared approval primitive, not a second review system.",[348,255,349,198,12],"human-review","inbox",{"path":351,"title":352,"description":353,"group":139,"section":299,"order":32,"tags":354,"lastUpdated":259},"\u002Fengineering\u002Fsystem-design\u002Fagentic-platform\u002Fproducts\u002Fsignals-search","Signals Search","One bounded discovery workflow that finds companies, verifies signals, finds relevant people, and produces evidence-backed organization prospects without prematurely creating CRM records.",[303,355,36,119,51,302,256,11,35],"discovery",{"path":357,"title":358,"description":359,"group":139,"section":299,"order":360,"tags":361,"lastUpdated":188},"\u002Fengineering\u002Fsystem-design\u002Fagentic-platform\u002Fproducts\u002Fworkflow-visualizer","Workflow visualizer","One constrained workflow graph, reused to author a draft, read a published definition, and watch a Run. Build mode edits the draft; run mode overlays Run and span state on the frozen snapshot.",7,[312,362,258,311,217,282,363,255],"visualizer","graph",{"path":365,"title":366,"description":367,"group":139,"section":181,"order":368,"tags":369,"lastUpdated":201},"\u002Fengineering\u002Fsystem-design\u002Fagentic-platform\u002Fruntime\u002Fdefinitions","Runtime definitions","Editable drafts, one published configuration per definition, template forks, deterministic validation, and the Run snapshot that keeps in flight work stable.",8,[149,311,329,370],"publishing",{"path":372,"title":373,"description":374,"group":139,"section":181,"order":375,"tags":376,"lastUpdated":259},"\u002Fengineering\u002Fsystem-design\u002Fagentic-platform\u002Fruntime\u002Fexecution","Runtime execution","The Run record, the Inngest step boundaries, agent segments, workflow nodes, approvals, cancellation, failure handling and live events.",9,[149,217,197,142,255,377,64],"cancellation",{"path":379,"title":380,"description":381,"group":139,"section":181,"order":360,"tags":382,"lastUpdated":285},"\u002Fengineering\u002Fsystem-design\u002Fagentic-platform\u002Fruntime","Agentic runtime","One Run contract, one Agno agent runtime, one deterministic workflow model, and the component boundaries that keep the framework replaceable.",[149,217,197,312,207,142],{"path":384,"title":385,"description":386,"group":139,"section":387,"order":244,"tags":388,"lastUpdated":392},"\u002Fengineering\u002Fsystem-design\u002Fmission-control\u002Fcompany-context","Company context","L3. Company state, knowledge and memory are three different things. One deterministic builder turns them into one brief.","Mission Control",[389,390,186,185,184,391,11],"mission-control","company-state","retrieval","2026-08-12",{"path":394,"title":395,"description":396,"group":139,"section":387,"order":22,"tags":397,"lastUpdated":392},"\u002Fengineering\u002Fsystem-design\u002Fmission-control\u002Fexperience","Experience","L6. Where a person observes and controls the company, and the one rule that keeps the UI out of the business.",[389,398,399,255,400],"ui","control-plane","activity",{"path":402,"title":403,"description":404,"group":139,"section":387,"order":222,"tags":405,"lastUpdated":392},"\u002Fengineering\u002Fsystem-design\u002Fmission-control\u002Ffoundation","Foundation","L1. Generic infrastructure with no business logic in it. The test is that another product could run on it unchanged.",[389,406,407,408,267,409,226,209],"infrastructure","database","queue","storage",{"path":411,"title":387,"description":412,"group":139,"section":214,"order":233,"tags":413,"lastUpdated":392},"\u002Fengineering\u002Fsystem-design\u002Fmission-control","The internal Company OS. Six layers and one policy plane put a person in control of company state and of autonomous execution.",[389,414,14,12,312,198,399],"company-os",{"path":416,"title":417,"description":418,"group":139,"section":387,"order":32,"tags":419,"lastUpdated":392},"\u002Fengineering\u002Fsystem-design\u002Fmission-control\u002Fintelligence","Intelligence","L5. The agent is the primitive. A skill is how it works, a tool is how it reaches the world, and the two are never the same thing.",[389,12,207,420,421],"planning","reasoning",{"path":423,"title":424,"description":425,"group":139,"section":387,"order":368,"tags":426,"lastUpdated":392},"\u002Fengineering\u002Fsystem-design\u002Fmission-control\u002Fmetrics-and-connectors","Metrics and connectors","A worked example across every layer. Three vendors, one metric pipeline, three views, and the rule that decides what we store.",[389,427,195,428,429,284,430,431],"metrics","stripe","posthog","ingest","dashboards",{"path":433,"title":434,"description":435,"group":139,"section":387,"order":233,"tags":436,"lastUpdated":392},"\u002Fengineering\u002Fsystem-design\u002Fmission-control\u002Forchestration","Orchestration","L4. Workflow, run, step, trigger and event. Five nouns that turn a decision into durable execution.",[389,312,217,266,267,437,438],"durability","retry",{"path":440,"title":288,"description":441,"group":139,"section":387,"order":360,"tags":442,"lastUpdated":392},"\u002Fengineering\u002Fsystem-design\u002Fmission-control\u002Fpolicy-and-governance","A plane, not a layer. One place decides what an agent may do, under what conditions, and how much. Human approval is one of its three answers.",[389,198,294,255,292,293,443],"audit",{"path":445,"title":191,"description":446,"group":139,"section":387,"order":264,"tags":447,"lastUpdated":392},"\u002Fengineering\u002Fsystem-design\u002Fmission-control\u002Ftools-and-integrations","L2. One contract for every capability. The tool is the only route to the world, and it is where policy, audit and tenancy meet.",[389,194,195,448,449,450],"adapters","registry","credentials",{"path":452,"title":453,"description":454,"group":139,"section":455,"order":22,"tags":456,"lastUpdated":210},"\u002Fengineering\u002Fsystem-design\u002Fworkflows\u002Fcompany-search","Company search","Implementation notes for company.search. Search resolves and gates company identities; enrichment is a separate capability.","Workflows",[321,457,142,42],"search",{"path":459,"title":31,"description":460,"group":139,"section":455,"order":233,"tags":461,"lastUpdated":210},"\u002Fengineering\u002Fsystem-design\u002Fworkflows\u002Fenrichment","Reusable company and people enrichment workflows with canonical Intelligence write-back, existing tier freshness and bounded asynchronous email.",[35,321,119,142],{"path":463,"title":464,"description":465,"group":139,"section":455,"order":32,"tags":466,"lastUpdated":259},"\u002Fengineering\u002Fsystem-design\u002Fworkflows\u002Fpeople-search","People search","Implementation notes for people.search. Bounded company scope and persona gates return selectable person identities without enrichment.",[119,457,142,100],{"path":468,"title":469,"description":470,"group":139,"section":455,"order":244,"tags":471,"lastUpdated":474},"\u002Fengineering\u002Fsystem-design\u002Fworkflows\u002Fsignals-search","Signals search","Superseded. The earlier on-demand buying-signal search component, kept as a record of the design that the agentic platform Signals Search workflow replaces.",[51,12,142,472,473],"intelligence-databases","superseded","2026-08-28",{"path":476,"title":477,"description":478,"group":479,"section":480,"order":481,"tags":482,"lastUpdated":66},"\u002Flearnings\u002Fagentic-sdlc","The agentic SDLC","How AI agents move from autocomplete to owning the loop across the software lifecycle, and why that shifts the bottleneck from coding to verification.","Learnings",null,30,[12,483,484,485,486],"sdlc","engineering","verification","review",{"path":488,"title":489,"description":490,"group":479,"section":480,"order":491,"tags":492,"lastUpdated":498},"\u002Flearnings\u002Fagi-to-asi","From AGI to ASI","What lies beyond human-level AI. The four technological pathways from AGI to artificial superintelligence, the formal ceiling that bounds them, and the six bottlenecks that could stall the climb - distilled from the DeepMind report.",50,[493,494,495,496,497],"ai-futures","asi","agi","scaling","recursive-self-improvement","2026-06-19",{"path":500,"title":501,"description":502,"group":479,"section":480,"order":503,"tags":504,"lastUpdated":66},"\u002Flearnings\u002Fai-native-company-playbook","AI native company playbook","Why AI should be the operating system your company runs on, not a tool it uses, and the concrete practices that follow - closed loops, a queryable org, software factories, and token maxing.",40,[505,506,12,507,508],"ai-native","company-building","gtm","founders",{"path":510,"title":511,"description":512,"group":479,"section":480,"order":157,"tags":513,"lastUpdated":54},"\u002Flearnings\u002Fbuying-intent-signals","Buying intent signals","How buyers leak their intent before they ever fill in a form, and how to read those signals before the window closes.",[514,51,507,515],"intent","sales",{"path":517,"title":518,"description":519,"group":479,"section":480,"order":520,"tags":521,"lastUpdated":54},"\u002Flearnings\u002Fcold-outbound-system","Cold outbound system","A high-level study of an open-source 29-skill cold email system, organized into five sequential tracks from ICP to iteration.",20,[522,523,507,524],"outbound","cold-email","systems",{"path":526,"title":527,"description":528,"group":479,"section":480,"order":529,"tags":530,"lastUpdated":532},"\u002Flearnings\u002Fswan-gtm-skills-architecture","Swan GTM skills architecture","A research note on Swan AI's foundations and maps model for GTM agents, with ASCII diagrams and ideas AgencyCore can borrow.",60,[507,12,73,531,14],"swan","2026-07-01",{"path":534,"title":535,"description":536,"group":387,"section":480,"order":272,"tags":537,"lastUpdated":43},"\u002Fmission-control\u002Fciops-agent","CIOps agent","High-level system architecture and design notes for the Mission Control CIOps agent.",[389,12,538,14],"ciops",{"path":540,"title":541,"description":542,"group":387,"section":480,"order":182,"tags":543,"lastUpdated":43},"\u002Fmission-control\u002Fcostops-agent","CostOps agent","High-level system architecture and design notes for the Mission Control CostOps agent.",[389,12,544,14],"finops",{"path":546,"title":547,"description":548,"group":387,"section":480,"order":520,"tags":549,"lastUpdated":54},"\u002Fmission-control\u002Fdashboard","Dashboard","The Mission Control product UI - a dark cockpit with a fleet-nav rail, company-state grid, a working escalation queue, live ledger and a global kill switch.",[389,12,550,398],"dashboard",{"path":552,"title":553,"description":554,"group":387,"section":480,"order":280,"tags":555,"lastUpdated":43},"\u002Fmission-control\u002Fproduct-analytics-agent","ProductAnalytics agent","High-level system architecture and design notes for the Mission Control ProductAnalytics agent.",[389,12,556,14],"product-analytics",{"path":558,"title":559,"description":560,"group":387,"section":480,"order":290,"tags":561,"lastUpdated":43},"\u002Fmission-control\u002Frevenueops-agent","RevenueOps agent","High-level system architecture and design notes for the Mission Control RevenueOps agent.",[389,12,562,14],"revops",{"path":564,"title":214,"description":565,"group":387,"section":480,"order":157,"tags":566,"lastUpdated":54},"\u002Fmission-control\u002Fsystem-design","One screen for the whole company, watched by a guardrailed fleet of ops agents that explain, propose, act and learn overnight.",[389,12,544,14],{"path":568,"title":569,"description":570,"group":571,"section":480,"order":32,"tags":572,"lastUpdated":578},"\u002Fproduct-design\u002Fonboarding-flow","Onboarding flow","Product design for the signup wizard and how TAM building folds into it. Analyzes the flow today (account, profile, company), the gap (no ICP, empty dashboard), and the integration of a new \"who you sell to\" ICP step plus a build-and-reveal screen that lands the user on a populated, ranked list.","Product Design",[573,61,574,575,576,577],"onboarding","tam","activation","ux","user-journey","2026-06-11",{"path":580,"title":581,"description":582,"group":571,"section":480,"order":233,"tags":583,"lastUpdated":592},"\u002Fproduct-design\u002Fpricing-entitlements","Pricing tiers, entitlements and usage credits","Specification for subscription tiers with gated platform access: composable plan entitlements, a unified usage-credit currency, plan-sourced limits, per-module trials and a two-ticket delivery plan built on the Stripe billing foundation. Written for discussion; the Linear document is the canonical copy with ticket links.",[584,585,586,587,588,589,590,591],"pricing","entitlements","billing","credits","subscriptions","plans","seats","trials","2026-07-06",{"path":594,"title":595,"description":596,"group":571,"section":480,"order":233,"tags":597,"lastUpdated":578},"\u002Fproduct-design\u002Fsales-signals-ux","Designing Signals","Product design for the sales-signals experience in ac-frontend: the 14-type taxonomy and its color system, the anatomy of a signal card across four densities, the 0-10 lead score scale, the origin tag (sonar pull vs proactive push), the seven surfaces where signals render (launchpad, sonar app, company detail, timeline, activities, data layer, Envoy), and the interaction rules that keep them consistent.",[51,576,598,11,42,599,600,601,602],"design-system","lead-score","origin","pull","push",{"path":604,"title":605,"description":606,"group":607,"section":608,"order":244,"tags":609,"lastUpdated":43},"\u002Fproprietary-data\u002Fcrm\u002Factivities","Activities","Deep dive on crm_activities, the interaction + task log of the CRM — where it is served from, how a row is born and read, and its full schema, relationships and rules.","Proprietary data","CRM",[11,610,611,612,613],"activities","tasks","data-model","schema",{"path":615,"title":616,"description":617,"group":607,"section":608,"order":264,"tags":618,"lastUpdated":43},"\u002Fproprietary-data\u002Fcrm\u002Fcommunications","Communications","Deep dive on crm_communications and crm_communication_events, the unified email\u002Fcall\u002Fmessage log and its per-message engagement tracking — where it is served from, the outbound message lifecycle, and the full schema, relationships and rules.",[11,619,336,620,612],"communications","engagement",{"path":622,"title":623,"description":624,"group":607,"section":608,"order":22,"tags":625,"lastUpdated":43},"\u002Fproprietary-data\u002Fcrm\u002Fcompanies","Companies","Deep dive on crm_companies, the account record at the centre of the CRM — where it is served from, how a row is born and read, and its full schema, relationships and rules.",[11,36,612,613,14],{"path":627,"title":628,"description":629,"group":607,"section":608,"order":233,"tags":630,"lastUpdated":43},"\u002Fproprietary-data\u002Fcrm\u002Fdeals","Deals","Deep dive on the deal pipeline — crm_deals, crm_pipeline_stages and crm_pipeline_config. Where it is served from, the life of a deal, and its full schema, relationships and rules.",[11,631,632,612,613],"deals","pipeline",{"path":634,"title":635,"description":636,"group":607,"section":608,"order":222,"tags":637,"lastUpdated":43},"\u002Fproprietary-data\u002Fcrm\u002Flists","Lists","Deep dive on crm_lists and crm_list_members, the static or dynamic member collections of the CRM — where they are served from, how a list and its members come to be and are read, and their schema, relationships and rules.",[11,638,639,612,613],"lists","segments",{"path":641,"title":642,"description":643,"group":607,"section":608,"order":32,"tags":644,"lastUpdated":43},"\u002Fproprietary-data\u002Fcrm\u002Fpeople","People","Deep dive on crm_people, the contact record of the CRM — where it is served from, how a row is born and read, and its full schema, relationships and rules.",[11,119,645,612,613],"contacts",{"path":647,"title":648,"description":649,"group":607,"section":608,"order":368,"tags":650,"lastUpdated":43},"\u002Fproprietary-data\u002Fcrm\u002Fsaved-filters","Saved filters","Deep dive on crm_saved_filters, the named reusable filter snapshots over the company, person and signal list views — where it is served from, how a saved view is born and applied, and its full schema, relationships and rules.",[11,651,652,612,613],"saved-filters","views",{"path":654,"title":655,"description":656,"group":607,"section":608,"order":360,"tags":657,"lastUpdated":578},"\u002Fproprietary-data\u002Fcrm\u002Fsignals","Signals","Deep dive on the signals tables - signals, company_signals and person_signals, the CRM's sales-intelligence layer. Where signals are served from, how one is born and attached, and the full schema, relationships and rules.",[11,51,302,612,613],{"path":659,"title":660,"description":661,"group":607,"section":662,"order":22,"tags":663,"lastUpdated":43},"\u002Fproprietary-data\u002Fintelligence-databases\u002Fcompany-intelligence-database","Company Intelligence Database","Decided architecture for ENG-669, the cross-org company intelligence layer that acts as a read-through cache in front of enrichment providers, with public-facts-only privacy and provenance-tracked write-back.","Intelligence databases",[14,60,36,51,38,664],"eng-669",{"path":666,"title":667,"description":668,"group":607,"section":662,"order":244,"tags":669,"lastUpdated":578},"\u002Fproprietary-data\u002Fintelligence-databases\u002Forg-signal-feed","Org Signal Feed","The per-org activation layer on top of the shared signals store. One immutable intel_signals row fans out to many orgs through scoring (signal-type weight times ICP fit times recency decay) and materializes as ranked, tiered rows in intel_org_signal_feed - the only org-scoped, RLS-per-org table of the signal stack, the door the launchpad, inbox and digest all read through. Signals enter by two ingest classes - a user's sonar pull (ungated) or an automated push (gated by threshold plus an optional competitor-ICP check) - logged in intel_signal_ingests, and each feed row records its origin.",[14,60,51,670,53,671,672,575,430,601,602,600],"feed","decay","rls",{"path":674,"title":675,"description":676,"group":607,"section":662,"order":32,"tags":677,"lastUpdated":578},"\u002Fproprietary-data\u002Fintelligence-databases\u002Fpeople-intelligence-database","People Intelligence Database","Decided architecture for the cross-org people intelligence layer - a read-through cache in front of headhunter research and Hunter email lookups, with LinkedIn-URL identity, append-only employment edges, per-tier freshness stamps on the flat profile, shared intel_sources provenance, unified intel_signals, and a GDPR erasure path.",[14,60,119,51,38,100],{"path":679,"title":680,"description":681,"group":607,"section":662,"order":233,"tags":682,"lastUpdated":578},"\u002Fproprietary-data\u002Fintelligence-databases\u002Fsignals-intelligence-database","Signals Intelligence Database","Decided v1 architecture for the unified signal store - one polymorphic append-only intel_signals table that holds both company and person signals, with a shared taxonomy, source-ranked provenance, an intel_signal_ingests log that records which pipeline found each signal, decay at read time, and a person-to-company rollup so a champion job change surfaces on the company feed.",[14,60,51,683,671,684,670,685,41,601,602],"polymorphic","taxonomy","ingests",{"path":687,"title":688,"description":689,"group":607,"section":480,"order":9,"tags":690,"lastUpdated":16},"\u002Fproprietary-data\u002Foverview","Data Layer Overview","The AgencyCore data layer in one map - the org-scoped CRM plane in production today and the global intelligence plane designed to sit in front of it, with interactive diagrams of both, the end-to-end data flow, freshness and precedence rules, the privacy seam, and the rollout path.",[691,14,60,11,51,38,25,216],"data-layer",{"path":693,"title":694,"description":695,"group":696,"section":480,"order":9,"tags":697,"lastUpdated":54},"\u002Froadmap","Roadmap - June 2026","June 2026 product plan across four themes. The spine is moving our agents onto an isolated sandbox runtime and rebuilding the core agents and workflows on it, then standing up a read-through intelligence data store and shipping the Stripe billing system. Knowledge base, assistant, and credit tracking carry into the July roadmap.","Roadmap",[698,420],"roadmap",{"path":700,"title":701,"description":702,"group":696,"section":480,"order":22,"tags":703,"lastUpdated":54},"\u002Froadmap\u002Fjuly-2026","Roadmap - July 2026","July 2026 product plan across three themes, all carried over from June. Building on June's sandbox runtime, July grounds the agents in a knowledge base, launches the AI chat assistant, and meters every action with per-action credit tracking that reconciles into the Stripe billing system shipped in June.",[698,420],{"path":705,"title":706,"description":707,"group":696,"section":480,"order":32,"tags":708,"lastUpdated":532},"\u002Froadmap\u002Fjune-2026-slides","Roadmap slides - June 2026","Board-review slide deck for the June 2026 product roadmap, rendered directly from the original PPTX in the docs site.",[698,420,709],"slides",{"path":711,"title":712,"description":713,"group":714,"section":8,"order":520,"tags":715,"lastUpdated":16},"\u002Fsymphony\u002Fagents\u002Fdevops-agent","DevOps agent","Interactive design for a Slack-first Symphony DevOps agent that wraps production promotion, rollback, audit, and operational jobs behind policy gates, typed runbooks, and an auditable ledger.","Symphony",[716,235,717,718,719,720],"symphony","devops","production","runbooks","operations",{"path":722,"title":723,"description":724,"group":714,"section":8,"order":157,"tags":725,"lastUpdated":16},"\u002Fsymphony\u002Fagents\u002Foncall-agent","Oncall agent","Interactive design for a Symphony oncall agent that turns Sentry incidents into rich Linear tickets, investigates with Codex, opens fix PRs, and resolves Sentry after merge.",[716,284,726,727,728,729],"linear","oncall","incident-response","codex",{"path":731,"title":732,"description":733,"group":714,"section":734,"order":157,"tags":735,"lastUpdated":16},"\u002Fsymphony\u002Fhousekeeping\u002Fcodex-vacuum","Codex vacuum","Interactive design for the Symphony housekeeping timer that checkpoints and vacuums Codex sqlite stores on the VPS.","Housekeeping",[716,736,737,729,738,739],"timed-jobs","housekeeping","sqlite","vps",{"path":741,"title":742,"description":743,"group":714,"section":734,"order":481,"tags":744,"lastUpdated":16},"\u002Fsymphony\u002Fhousekeeping\u002Fhost-cleanup","Host cleanup","Interactive design for the Symphony housekeeping timer that removes stale \u002Ftmp debris, vacuums the journal, and optionally cleans the apt package cache.",[716,736,737,739,745,746],"disk","cleanup",{"path":748,"title":749,"description":750,"group":714,"section":734,"order":520,"tags":751,"lastUpdated":16},"\u002Fsymphony\u002Fhousekeeping\u002Fworkspace-cleanup","Workspace cleanup","Interactive design for the Symphony housekeeping timer that prunes idle per-issue workspaces after their TTL.",[716,736,737,752,746,739],"workspaces",{"path":754,"title":755,"description":756,"group":714,"section":480,"order":9,"tags":757,"lastUpdated":66},"\u002Fsymphony","Symphony orchestration","How AgencyCore runs OpenAI Symphony as a long-running daemon that turns Linear tickets into isolated, autonomous Codex runs, reviewed by Claude and merged by humans. High-level workflow, system architecture, and the engineer playbook.",[716,729,726,758,111,739,759,760],"claude-review","qa","automation",{"path":762,"title":763,"description":764,"group":714,"section":214,"order":22,"tags":765,"lastUpdated":392},"\u002Fsymphony\u002Fsystem-design\u002Fhigh-level-design","High-level design","The Symphony daemon end to end — the standing agent workforce and its label-routed workflows, then the runtime that polls, dispatches, runs and writes back.",[716,14,111,12,729,726,766],"systemd",{"path":768,"title":769,"description":770,"group":714,"section":771,"order":503,"tags":772,"lastUpdated":16},"\u002Fsymphony\u002Ftimed-jobs\u002Fdaily-security-agent","Daily security agent","Interactive design for a report-only Symphony timed job that reviews the last 24h of commits, scans the system for vulnerabilities, and opens focused follow-up tickets.","Timed jobs",[716,199,736,729,773,774,775],"semgrep","threat-model","ownership",{"path":777,"title":778,"description":779,"group":714,"section":771,"order":481,"tags":780,"lastUpdated":16},"\u002Fsymphony\u002Ftimed-jobs\u002Fdaily-sentry-triage","Daily Sentry triage","Interactive design for the Symphony timed job that performs read-only Sentry triage, deduplicates existing tracked clusters, and creates focused ENG bugs for new actionable errors.",[716,736,284,209,781,726],"triage",{"path":783,"title":784,"description":785,"group":714,"section":771,"order":157,"tags":786,"lastUpdated":16},"\u002Fsymphony\u002Ftimed-jobs\u002Fnightly-local-staging-e2e","Nightly local staging E2E","Interactive design for the Symphony timed job that seeds local Supabase, runs ac-frontend Playwright E2E against the local staging stack, uploads evidence, and cleans artifacts.",[716,736,787,788,789,790],"e2e","playwright","staging","frontend",{"path":792,"title":793,"description":794,"group":714,"section":771,"order":520,"tags":795,"lastUpdated":16},"\u002Fsymphony\u002Ftimed-jobs\u002Fnightly-staging-qa","Nightly staging QA","Interactive design for the Symphony timed job that seeds a staging QA Linear issue, runs an agent-browser crawl, validates feature-map coverage, and files focused follow-up work.",[716,736,789,759,796,726],"agent-browser",{"id":798,"title":345,"body":799,"customComponent":480,"description":346,"extension":2345,"group":139,"lastUpdated":188,"meta":2346,"navigation":2347,"order":222,"path":344,"related":2348,"section":299,"seo":2357,"stem":2358,"tags":2359,"__hash__":2360},"docs\u002Fengineering\u002Fsystem-design\u002Fagentic-platform\u002Fproducts\u002Fhuman-review.md",{"type":800,"value":801,"toc":2309},"minimark",[802,806,818,821,832,835,841,849,852,857,860,884,887,889,893,898,974,988,1034,1058,1064,1070,1098,1102,1109,1112,1119,1184,1193,1199,1201,1205,1215,1219,1222,1248,1263,1267,1270,1327,1339,1346,1349,1351,1355,1359,1365,1368,1379,1383,1389,1392,1399,1401,1405,1530,1532,1536,1539,1542,1548,1557,1576,1595,1606,1627,1646,1659,1678,1681,1688,1690,1694,1701,1709,1712,1714,1718,1721,1725,1741,1752,1756,1768,1771,1773,1777,1780,1786,1789,1799,1802,1804,1808,1811,1873,1879,1881,1885,1971,1977,1979,1983,1989,2009,2017,2037,2056,2072,2079,2106,2109,2111,2115,2119,2125,2128,2132,2138,2145,2148,2155,2159,2165,2168,2172,2178,2181,2183,2187,2193,2196,2255,2258,2262,2268,2306],[803,804,345],"h1",{"id":805},"human-review-inbox",[807,808,809,813,814,817],"p",{},[810,811,812],"strong",{},"Status:"," accepted · ",[810,815,816],{},"Date:"," 2026-08-30",[807,819,820],{},"A dedicated product page where a person can see and resolve work the agentic platform has intentionally paused for human authorization.",[807,822,823,824,827,828,831],{},"The product name is ",[810,825,826],{},"Human Review",". The underlying platform surface is the ",[810,829,830],{},"Approval Inbox",".",[807,833,834],{},"The key rule is:",[836,837,838],"blockquote",{},[807,839,840],{},"If a Run is waiting because a person must approve or reject an exact proposed action, the approval appears here.",[807,842,843,844,848],{},"Human Review does not create a new workflow engine, task system, notification system, policy engine or approval store. It reads and resolves the same ",[845,846,847],"code",{},"agent.approvals"," rows used by Policy and Runtime.",[850,851],"hr",{},[853,854,856],"h2",{"id":855},"product-promise","Product promise",[807,858,859],{},"A user should be able to open one page and answer four questions immediately:",[861,862,863,869,874,879],"ol",{},[864,865,866],"li",{},[810,867,868],{},"What needs my decision?",[864,870,871],{},[810,872,873],{},"What exactly will happen if I approve?",[864,875,876],{},[810,877,878],{},"Why was human review required?",[864,880,881],{},[810,882,883],{},"Which Run is waiting for this decision?",[807,885,886],{},"Human Review is the guaranteed channel-independent fallback. In the current V1 slice, approval decisions are presented in web chat and this inbox. A later remote channel, such as Slack, may render the same decision, but every presentation resolves the same approval row.",[850,888],{},[853,890,892],{"id":891},"what-belongs-here","What belongs here",[894,895,897],"h3",{"id":896},"v1-review-types","V1 review types",[899,900,901,917],"table",{},[902,903,904],"thead",{},[905,906,907,911,914],"tr",{},[908,909,910],"th",{},"Review type",[908,912,913],{},"Example",[908,915,916],{},"Created at",[918,919,920,938,949,959],"tbody",{},[905,921,922,926,932],{},[923,924,925],"td",{},"Run admission",[923,927,928,929],{},"A wide or costly Signals Search, ",[810,930,931],{},"if current admission Policy requires approval",[923,933,934,937],{},[845,935,936],{},"RunManager.start()"," → Policy admission checkpoint",[905,939,940,943,946],{},[923,941,942],{},"External side effect",[923,944,945],{},"Send an Email Sequence message to a new recipient",[923,947,948],{},"Tool Invoker → Policy action checkpoint",[905,950,951,954,957],{},[923,952,953],{},"Sensitive CRM change",[923,955,956],{},"Move a protected customer lifecycle state",[923,958,948],{},[905,960,961,964,967],{},[923,962,963],{},"Authored gate",[923,965,966],{},"A workflow that must pause for a person before outreach",[923,968,969,970,973],{},"Workflow ",[845,971,972],{},"approval"," node",[807,975,976,977,980,981,983,984,987],{},"There are three V1 approval entry points. All three use ",[845,978,979],{},"ApprovalService",", write ",[845,982,847],{},", move the same Run into ",[845,985,986],{},"waiting",", and therefore appear in the same inbox.",[899,989,990,1002],{},[902,991,992],{},[905,993,994,999],{},[908,995,996],{},[845,997,998],{},"raised_by",[908,1000,1001],{},"Who decided a person is needed",[918,1003,1004,1014,1024],{},[905,1005,1006,1011],{},[923,1007,1008],{},[810,1009,1010],{},"admission",[923,1012,1013],{},"Policy, before a Run executes anything",[905,1015,1016,1021],{},[923,1017,1018],{},[810,1019,1020],{},"action",[923,1022,1023],{},"Policy, before a gated tool effect executes",[905,1025,1026,1031],{},[923,1027,1028],{},[810,1029,1030],{},"node",[923,1032,1033],{},"The workflow author, when the definition was written",[807,1035,1036,1044,1045,1047,1048,1050,1051,1054,1055,1057],{},[810,1037,1038,1040,1041,831],{},[845,1039,998],{}," is not ",[845,1042,1043],{},"PolicyRequest.checkpoint"," The policy checkpoints are ",[845,1046,1010],{},", ",[845,1049,1020],{}," and ",[845,1052,1053],{},"accrual",", and the engine never emits ",[845,1056,1030],{},", because a node approval is not a policy decision at all. Two overlapping vocabularies under one field name would read as one, and the audit trail would then claim policy required a gate the author wrote by hand.",[807,1059,1060,1061,1063],{},"The third one is not a policy decision, and that is the point. A rule can say \"an email to a new recipient needs approval\". It cannot say \"always stop here, in this workflow, whatever the arguments are\". An author who wants a fixed review gate declares an ",[845,1062,972],{}," node, and the runtime creates the same row.",[807,1065,1066,1067,1069],{},"The inbox does not care which of the three created the row. ",[845,1068,998],{}," records it for the audit trail.",[807,1071,1072,1073,1076,1077,1080,1081,1083,1084,1087,1088,1047,1091,1094,1095,831],{},"The Front Door does ",[810,1074,1075],{},"not"," decide approval conditions or raise its own approval. It delegates through ",[845,1078,1079],{},"StartRunCommand"," \u002F ",[845,1082,936],{},". ",[845,1085,1086],{},"RunManager"," owns the Run; Policy then decides ",[845,1089,1090],{},"allow",[845,1092,1093],{},"deny"," or ",[845,1096,1097],{},"require_approval",[894,1099,1101],{"id":1100},"future-review-types","Future review types",[807,1103,1104,1105,1108],{},"A future product feature may reuse the same approval primitive when it needs an explicit authorize\u002Freject decision. For example, an agent-proposed durable-memory write ",[810,1106,1107],{},"could"," use Human Review, but that has not been made a V1 requirement.",[807,1110,1111],{},"Do not add a new review queue merely because a new product needs a human decision.",[894,1113,1115,1116,1118],{"id":1114},"what-does-not-belong-here","What does ",[810,1117,1075],{}," belong here",[899,1120,1121,1131],{},[902,1122,1123],{},[905,1124,1125,1128],{},[908,1126,1127],{},"Item",[908,1129,1130],{},"Where it belongs",[918,1132,1133,1141,1149,1157,1165,1173],{},[905,1134,1135,1138],{},[923,1136,1137],{},"Agent needs missing information from the user",[923,1139,1140],{},"Originating conversation",[905,1142,1143,1146],{},[923,1144,1145],{},"Failed or unhealthy Run",[923,1147,1148],{},"Run Explorer",[905,1150,1151,1154],{},[923,1152,1153],{},"General notifications",[923,1155,1156],{},"Product notification system",[905,1158,1159,1162],{},[923,1160,1161],{},"Work someone should manually perform",[923,1163,1164],{},"Task system",[905,1166,1167,1170],{},[923,1168,1169],{},"Policy configuration",[923,1171,1172],{},"Admin policy settings",[905,1174,1175,1181],{},[923,1176,1177,1178],{},"Signals Search prospect curation: ",[845,1179,1180],{},"new \u002F watching \u002F dismissed \u002F promoted",[923,1182,1183],{},"Signals Search \u002F Opportunity Review",[807,1185,1186,1187,1190,1191,831],{},"The Signals Search review state is business curation over an ",[810,1188,1189],{},"Organization Prospect",". It is not execution authorization and must not be folded into ",[845,1192,847],{},[807,1194,1195,1198],{},[810,1196,1197],{},"Human Review is a decision inbox, not a general work inbox."," Every row here blocks a Run. A queue a person may ignore without stopping work belongs somewhere else.",[850,1200],{},[853,1202,1204],{"id":1203},"page-structure","Page structure",[1206,1207,1213],"pre",{"className":1208,"code":1210,"language":1211,"meta":1212},[1209],"language-text","Human Review\n┌─────────────────────────────────────────────────────────────────────┐\n│ [Pending]  [History]                                                │\n├────────────────────────────────────┬────────────────────────────────┤\n│ Send email to Sarah Chen           │ email.send                     │\n│ email.send · requested 4m ago      │                                │\n│ Expires in 56m                     │ Workflow: Email Sequence       │\n│                                    │ Target: Sarah Chen · Acme      │\n│ Search up to 5,000 companies       │                                │\n│ signals.search · requested 12m ago │ Why review is required         │\n│ Expires in 44m                     │ Wide run requires approval     │\n│                                    │ Rule ids, behind a disclosure  │\n│ Change lifecycle: Customer → ...   │                                │\n│ crm.company.update · 20m ago       │ Proposed action                │\n│ Expires in 40m                     │ ┌────────────────────────────┐ │\n│                                    │ │ exact proposed action      │ │\n│                                    │ └────────────────────────────┘ │\n│                                    │                                │\n│                                    │ Run: open in Run Explorer      │\n│                                    │ [Reject]           [Approve]   │\n└────────────────────────────────────┴────────────────────────────────┘\n","text","",[845,1214,1210],{"__ignoreMap":1212},[894,1216,1218],{"id":1217},"list-pane","List pane",[807,1220,1221],{},"Each row shows what the list projection carries, and nothing else:",[1223,1224,1225,1238,1242,1245],"ul",{},[864,1226,1227,1228,1231,1232,1231,1235,1237],{},"the row title, from ",[845,1229,1230],{},"preview",", then ",[845,1233,1234],{},"target_summary",[845,1236,1020],{},";",[864,1239,1240,1237],{},[845,1241,1020],{},[864,1243,1244],{},"the requested time;",[864,1246,1247],{},"the expiry state.",[807,1249,1250,1251,1254,1255,1258,1259,1262],{},"⚠️ ",[810,1252,1253],{},"The row names no Agent and no Workflow."," The list projection holds\n",[845,1256,1257],{},"run_id"," alone, so a name costs one ",[845,1260,1261],{},"GET \u002Fruns\u002F{run_id}"," for each row. One page\nholds fifty rows. The detail pane reads the run for the selected row instead.",[894,1264,1266],{"id":1265},"detail-pane","Detail pane",[807,1268,1269],{},"The detail contains enough information to decide without reading the span tree:",[1223,1271,1272,1278,1283,1288,1294,1300,1306,1311,1319],{},[864,1273,1274,1275,1277],{},"the Agent or Workflow name, from one ",[845,1276,1261],{}," on the selected row;",[864,1279,1280,1282],{},[845,1281,1020],{},", the exact proposed action;",[864,1284,1285,1287],{},[845,1286,1234],{},", what the call acts on;",[864,1289,1290,1293],{},[845,1291,1292],{},"proposed_arguments",", the proposed content or change;",[864,1295,1296,1299],{},[845,1297,1298],{},"reason",", why a person was asked;",[864,1301,1302,1305],{},[845,1303,1304],{},"matched_policy_ids",", the rules that asked;",[864,1307,1308,1310],{},[845,1309,1257],{},", a link to the Run Explorer detail;",[864,1312,1313,1050,1316,1237],{},[845,1314,1315],{},"created_at",[845,1317,1318],{},"expires_at",[864,1320,1321,1080,1324,831],{},[810,1322,1323],{},"Approve",[810,1325,1326],{},"Reject",[807,1328,1250,1329,1332,1333,1335,1336,1338],{},[810,1330,1331],{},"There is no risk category and no severity label."," No column holds either\none. ",[845,1334,1020],{}," names the effect, and ",[845,1337,1298],{}," names the cause.",[807,1340,1341,1342,1345],{},"V1 definitions do not have a revision\u002Fhistory subsystem. Do not show an ",[845,1343,1344],{},"agent_version",". The originating Run already freezes the effective execution snapshot used by the work, so the review links to that Run for stable execution identity.",[807,1347,1348],{},"Run Explorer remains the place for spans, detailed execution history and debugging.",[850,1350],{},[853,1352,1354],{"id":1353},"core-interaction","Core interaction",[894,1356,1358],{"id":1357},"admission-approval","Admission approval",[1206,1360,1363],{"className":1361,"code":1362,"language":1211,"meta":1212},[1209],"Front Door \u002F Trigger\n       │\n       ▼\nStartRunCommand\n       │\n       ▼\nRunManager.start()\n       │\n       ├─ create\u002Ffreeze Run execution snapshot\n       ▼\nPolicy admission\n   ┌───────┼──────────────┐\n   ▼       ▼              ▼\n allow    deny     require_approval\n   │       │              │\n dispatch stop       agent.approvals\n                         │\n                         ▼\n                    Run = waiting\n                    dispatch, and wait\n                         │\n                         ▼\n                    Human Review\n                         │\n                    approve\u002Freject\n                         │\n                         ▼\n                  the wait resolves\n                         │\n                   execute \u002F stop\n",[845,1364,1362],{"__ignoreMap":1212},[807,1366,1367],{},"The Front Door only requested the Run. It does not own the approval state or waiting lifecycle.",[807,1369,1370,1371,1374,1375,831],{},"An admission approval dispatches its Inngest function immediately, and the function waits before its first step. That is what gives the approval an expiry owner: the wait timeout is the writer that marks it ",[845,1372,1373],{},"expired",". A waiting Run holds no worker. See ",[1376,1377,1378],"a",{"href":372},"runtime execution",[894,1380,1382],{"id":1381},"action-approval","Action approval",[1206,1384,1387],{"className":1385,"code":1386,"language":1211,"meta":1212},[1209],"Agent \u002F Workflow\n      │\n      ▼\nproposed Tool call\n      │\n      ▼\nTool Invoker → Policy action\n      │\n      └─ require_approval\n             │\n             ▼\n      persist exact proposal\n      + continuation identity\n             │\n             ▼\n      agent.approvals row\n      Run = waiting\n             │\n             ▼\n        Inngest wait\n             │\n      worker may disappear\n             │\n             ▼\n        Human Review\n        approve\u002Freject\n             │\n             ▼\n   fresh worker may resume\n   from durable Run state\n             │\n             ▼\n   revalidate → execute\u002Freject\n",[845,1388,1386],{"__ignoreMap":1212},[807,1390,1391],{},"An approval never executes a tool directly from the UI. The UI resolves the approval row. Runtime\u002FInngest own waiting and continuation; the Tool layer owns the eventual side effect.",[807,1393,1394,1395,1398],{},"Everything needed to resume must be durable ",[810,1396,1397],{},"before"," the worker enters the wait. A resumed worker uses the Run's frozen execution snapshot plus persisted continuation identity\u002Fstate; correctness never depends on the original in-memory Agno object surviving.",[850,1400],{},[853,1402,1404],{"id":1403},"resolution-and-execution-rules","Resolution and execution rules",[861,1406,1407,1413,1419,1425,1462,1468,1478,1491,1497,1503],{},[864,1408,1409,1412],{},[810,1410,1411],{},"Approve means approve this exact proposal."," The stored arguments\u002Fcontent hash is checked again before execution.",[864,1414,1415,1418],{},[810,1416,1417],{},"Target state is revalidated."," For a write\u002Fsend, if the relevant target state changed while waiting, fail closed and require a fresh approval rather than applying stale authorization.",[864,1420,1421,1424],{},[810,1422,1423],{},"Reject is explicit."," Silence never becomes consent.",[864,1426,1427,1430,1431,1433,1434,1436,1437,1094,1440,1443,1444,1446,1447,1047,1450,1453,1454,1457,1458,1461],{},[810,1428,1429],{},"Expiry is explicit, and it has an owner."," Every pending approval has a TTL, and an expired approval cannot execute. The Inngest wait timeout resolves the row to ",[845,1432,1373],{}," and releases the Run. A list query may derive the expired state from ",[845,1435,1318],{}," before that fires, so the queue never shows a dead row. No sweeper job exists, because every terminal state has a real writer: a person writes ",[845,1438,1439],{},"approved",[845,1441,1442],{},"rejected",", the wait timeout writes ",[845,1445,1373],{},", and ",[845,1448,1449],{},"RunManager.cancel()",[845,1451,1452],{},"RunManager.fail()"," and the segment supersede write ",[845,1455,1456],{},"cancelled",". An expired approval cannot execute, and a row a person answered inside its TTL still executes after the timeout fires: the execution check reads ",[845,1459,1460],{},"resolved_at",", never the clock.",[864,1463,1464,1467],{},[810,1465,1466],{},"Approval cannot increase authority."," The resolver must hold the permission needed for the underlying action.",[864,1469,1470,1473,1474,1477],{},[810,1471,1472],{},"Resolution is one atomic conditional state transition."," ",[845,1475,1476],{},"pending → approved | rejected | expired"," allows only one winner. A later resolver receives the already-resolved state.",[864,1479,1480,1483,1484,1487,1488],{},[810,1481,1482],{},"Approval and idempotency solve different problems."," Approval answers ",[810,1485,1486],{},"may this action happen?"," The shared Idempotency Service answers ",[810,1489,1490],{},"has this approved effect already happened?",[864,1492,1493,1496],{},[810,1494,1495],{},"Writes and sends remain idempotent after approval."," If a worker dies after a vendor accepts the effect but before local completion is recorded, retry must return\u002Frecover the prior result rather than repeat the effect.",[864,1498,1499,1502],{},[810,1500,1501],{},"Any supported surface resolves the same approval id."," Human Review and interactive channel actions are alternate presentations, not alternate decisions.",[864,1504,1505,1508,1509,1512,1513,1516,1517,1520,1521,1524,1525,1527,1528,831],{},[810,1506,1507],{},"One Run may hold several approvals, in sequence or at once."," An email sequence reaches several approvals one after another over a long Run. A workflow ",[845,1510,1511],{},"parallel"," node reaches several ",[810,1514,1515],{},"at the same time",", because each branch waits in place and its siblings keep running. Both are ordinary.",[1518,1519],"br",{},"The inbox lists each one as its own row, and they resolve in any order. The Run's ",[845,1522,1523],{},"waiting_ref_id"," names the oldest unresolved one, so a person opening the Run sees one thing to do, and the Run leaves ",[845,1526,986],{}," only when the last of them is answered. See ",[1376,1529,1378],{"href":372},[850,1531],{},[853,1533,1535],{"id":1534},"productapi-view","Product\u002FAPI view",[807,1537,1538],{},"Human Review is a view over the platform approval domain, not a new data model.",[807,1540,1541],{},"The API projection needs enough information to render the decision safely:",[1206,1543,1546],{"className":1544,"code":1545,"language":1211,"meta":1212},[1209],"ApprovalDetail\n  id\n  run_id                the Run a reader opens for the Agent or Workflow name\n  root_run_id           the top of the Run tree; a cancel filters on it\n\n  raised_by             admission | action | node\n  action                the tool name, or the definition action\n  target_summary?       what the call acts on, in words a person reads\n  preview?              the line a handler's approval_preview rendered\n  reason?               why a person was asked\n\n  proposed_arguments    the exact content the model proposed; redacted on read\n  arguments_hash        which call this approval covers\n  matched_policy_ids    the rules that asked; empty for a `node` approval\n\n  status                pending | approved | rejected | expired | cancelled\n  created_at            when the row was filed\n  expires_at\n  resolved_at?\n  resolved_by?          the person who decided; null after that account is deleted\n",[845,1547,1545],{"__ignoreMap":1212},[807,1549,1250,1550,1556],{},[810,1551,1552,1555],{},[845,1553,1554],{},"organization_id"," is a filter and never a field."," The token names the\norganization, and the repository applies it to every read. A response that\nechoed it would tell a caller nothing it did not send.",[807,1558,1559,1560,1047,1562,1047,1564,1047,1567,1047,1569,1572,1573,1575],{},"The list row is the same shape without ",[845,1561,1298],{},[845,1563,1292],{},[845,1565,1566],{},"arguments_hash",[845,1568,1304],{},[845,1570,1571],{},"root_run_id"," and the two resolution fields. A person triages on the action, the target, the request time and the expiry. ",[845,1574,1298],{}," is a sentence, so it reads in the detail and not in a row.",[807,1577,1250,1578,1584,1585,1588,1589,1591,1592,1594],{},[810,1579,1580,1583],{},[845,1581,1582],{},"status"," is derived, and the stored column is not always the answer."," A row that reads ",[845,1586,1587],{},"pending"," and whose ",[845,1590,1318],{}," has passed answers ",[845,1593,1373],{},". The wait timeout is the writer of that column, and it has not fired yet.",[807,1596,1597,1598,1601,1602,1605],{},"The projection carries no ",[845,1599,1600],{},"continuation"," and no ",[845,1603,1604],{},"idempotency_key",". Both are runtime plumbing.",[807,1607,1608,1473,1617,1620,1621,1050,1623,1626],{},[810,1609,1610,1611,1601,1614,831],{},"There is no ",[845,1612,1613],{},"definition_id",[845,1615,1616],{},"action_category",[845,1618,1619],{},"agent.runs"," pairs its definition key with ",[845,1622,1554],{},[845,1624,1625],{},"kind",", and this table holds no kind, so a paired key has no target here. A single column key would let an approval name another tenant's definition. The Run answers the definition instead.",[807,1628,1629,1473,1632,1634,1635,1638,1639,1642,1643,1645],{},[810,1630,1631],{},"There is a policy column, since ENG-2169.",[845,1633,1304],{}," records every rule that matched the decision the row was filed for. ",[845,1636,1637],{},"ToolInvoker"," reads it before an approved call runs (check 6 in ",[1376,1640,1641],{"href":287},"policy and governance","), and ",[845,1644,1298],{}," names the winner only in words, so a person who wants the rule itself needs the id. It carries no foreign key: a deleted rule must not take the record of what it once gated.",[807,1647,1648,1650,1651,1654,1655,1658],{},[845,1649,1571],{}," is denormalized here for the same reason ",[845,1652,1653],{},"agent.spans"," carries it: cancelling a Run must clear its pending approvals in one statement, and a filter listing five hundred child Run IDs is an 18 KB URL that PostgREST answers with ",[845,1656,1657],{},"414",". It is kept true by the composite foreign key to the Run, never by a copy.",[807,1660,1661,1663,1664,1667,1668,1671,1672,1675,1676,831],{},[845,1662,1604],{}," is a ",[810,1665,1666],{},"column and not a field of the projection",". It is the tool journal key, ",[845,1669,1670],{},"\u003Crun_id>:\u003Cstep_path>:\u003Cargs_hash>",", and the uniqueness is what stops a replayed segment filing the same proposal twice. A pending approval is a proposed effect rather than an executed one, so ",[845,1673,1674],{},"agent.idempotency_keys"," does not hold it and this row carries the guard instead. See ",[1376,1677,1378],{"href":372},[807,1679,1680],{},"The durable execution identity is the Run and its frozen snapshot. Human Review must not create a parallel definition or version record.",[807,1682,1683,1684,1687],{},"Do not introduce a ",[845,1685,1686],{},"human_reviews"," table.",[850,1689],{},[853,1691,1693],{"id":1692},"api-contract","API contract",[807,1695,1696,1697,1700],{},"Human Review already speaks the AgencyCore schema, so it calls the approval domain API directly. It does not pass through Channel Gateway, and it gets no ",[845,1698,1699],{},"ApprovalInboxService"," UI-specific backend layer.",[807,1702,1703,1705,1706,1708],{},[1376,1704,250],{"href":249}," owns the routes and the API rules. ",[1376,1707,288],{"href":287}," owns what one resolution checks, and what writes each terminal state. This page adds nothing to either, and it must not restate them.",[807,1710,1711],{},"One consequence is worth naming here, because it shapes the page. A repeated resolution returns the current resolved state. That atomicity is not side-effect idempotency, and the execution path still uses the shared Idempotency Service.",[850,1713],{},[853,1715,1717],{"id":1716},"filtering-and-ordering","Filtering and ordering",[807,1719,1720],{},"V1 stays small.",[894,1722,1724],{"id":1723},"default-ordering","Default ordering",[807,1726,1727,1728,1730,1731,1734,1735,1737,1738,1740],{},"One sort key: ",[845,1729,1318],{}," ascending, then ",[845,1732,1733],{},"id",". The soonest expiry comes first, and ",[845,1736,1733],{}," breaks a tie two approvals of one ",[845,1739,1511],{}," node share.",[807,1742,1250,1743,1473,1746,1748,1749,1751],{},[810,1744,1745],{},"The tie break is not \"oldest first\".",[845,1747,1733],{}," is a random UUID, so two rows of one expiry come back in an arbitrary but stable order. Expiry order is not request order either: the TTL of the rule and the deadline of the run both set the expiry, so a later request can expire first. ",[1376,1750,250],{"href":249}," holds the rule.",[894,1753,1755],{"id":1754},"filters","Filters",[807,1757,1758,1759,1761,1762,1764,1765,1767],{},"V1 ships ",[845,1760,1582],{}," plus the cursor, and ",[845,1763,1582],{}," defaults to ",[845,1766,1587],{},". The queue is short, so category filters wait until a customer needs them.",[807,1769,1770],{},"No saved views, team queues or custom routing in V1.",[850,1772],{},[853,1774,1776],{"id":1775},"notifications-and-presentation-surfaces","Notifications and presentation surfaces",[807,1778,1779],{},"Human Review is always available, but an approval may first be surfaced elsewhere.",[1206,1781,1784],{"className":1782,"code":1783,"language":1211,"meta":1212},[1209],"approval created\n      │\n      ├── Human Review: always available\n      │\n      └── interactive channel presentation, when supported\n            ├── web chat\n            ├── Slack\n            └── other Channel Gateway adapters as capabilities allow\n",[845,1785,1783],{"__ignoreMap":1212},[807,1787,1788],{},"Interactive channel buttons go through the Channel Gateway's deterministic action handling and resolve the same approval id.",[807,1790,1791,1794,1795,1798],{},[810,1792,1793],{},"Email is not a Channel Gateway channel."," Nylas owns email transport and email Tools\u002Fevents. Email Sequence may show a product banner\u002Flink such as ",[810,1796,1797],{},"Review draft"," that opens Human Review, but email approval does not become a Channel Gateway path.",[807,1800,1801],{},"Do not build a second approval-notification system for this feature.",[850,1803],{},[853,1805,1807],{"id":1806},"rules-the-page-follows","Rules the page follows",[807,1809,1810],{},"Five rules, and each one answers a way the page can lie to a person.",[861,1812,1813,1823,1829,1843,1865],{},[864,1814,1815,1818,1819,1822],{},[810,1816,1817],{},"The response is the truth, and the page never assumes a decision won."," Three rows answer ",[845,1820,1821],{},"200"," with a status nobody chose: a row whose expiry passed, a row another surface resolved, and a row a Run cancelled. The page renders the status the response carried. An optimistic update tells a person they approved work that never ran.",[864,1824,1825,1828],{},[810,1826,1827],{},"The Approve button never reads the browser clock."," The two clocks differ. A button that a skewed clock disables hides a row the API resolves. The countdown is decoration, and the request is the test.",[864,1830,1831,1473,1837,1839,1840,1842],{},[810,1832,1833,1834,1836],{},"A ",[845,1835,1030],{}," approval names no rule.",[845,1838,1304],{}," is empty and ",[845,1841,1298],{}," may be null, because no rule produced the decision. The detail then says a workflow author required the review.",[864,1844,1845,1854,1855,1858,1859,1861,1862,1864],{},[810,1846,1847,1848,1231,1850,1231,1852,831],{},"The row title has one precedence: ",[845,1849,1230],{},[845,1851,1234],{},[845,1853,1020],{}," A tool that declares no ",[845,1856,1857],{},"approval_preview"," leaves ",[845,1860,1230],{}," null. ",[845,1863,1020],{}," is the one field that is never null.",[864,1866,1867,1872],{},[810,1868,1869,1871],{},[845,1870,1292],{}," is unbounded."," It holds an email body. The pane caps the height and puts the rest behind a disclosure.",[807,1874,1875,1878],{},[810,1876,1877],{},"The inbox has no live channel."," A Run stream is keyed on one Run, and this page lists the approvals of many Runs. So the page reads the list again: after each decision, and on an interval while the tab has focus. V1 adds no organization channel for this.",[850,1880],{},[853,1882,1884],{"id":1883},"empty-stale-restart-and-race-states","Empty, stale, restart and race states",[899,1886,1887,1897],{},[902,1888,1889],{},[905,1890,1891,1894],{},[908,1892,1893],{},"State",[908,1895,1896],{},"Product behavior",[918,1898,1899,1907,1915,1923,1931,1939,1947,1955,1963],{},[905,1900,1901,1904],{},[923,1902,1903],{},"No pending approvals",[923,1905,1906],{},"Show a simple empty state: \"Nothing needs review.\"",[905,1908,1909,1912],{},[923,1910,1911],{},"Approval expired",[923,1913,1914],{},"Remove from default queue; show as expired in History",[905,1916,1917,1920],{},[923,1918,1919],{},"Run cancelled",[923,1921,1922],{},"Approval is non-actionable\u002Fcancelled",[905,1924,1925,1928],{},[923,1926,1927],{},"Another surface resolved it",[923,1929,1930],{},"Render the status the response carried; do not present it as an error",[905,1932,1933,1936],{},[923,1934,1935],{},"Proposal changed",[923,1937,1938],{},"Block execution and require a fresh approval",[905,1940,1941,1944],{},[923,1942,1943],{},"Target state changed",[923,1945,1946],{},"Fail closed and require a fresh approval when appropriate",[905,1948,1949,1952],{},[923,1950,1951],{},"User lacks permission",[923,1953,1954],{},"V1 checks visibility alone, so every member may decide. The scope of the approver is checked before the effect runs, and a call it does not cover is refused there",[905,1956,1957,1960],{},[923,1958,1959],{},"Worker restarted while waiting",[923,1961,1962],{},"No user-visible failure; a fresh worker resumes from durable Run\u002Fcontinuation state after resolution",[905,1964,1965,1968],{},[923,1966,1967],{},"Worker dies after approved vendor effect",[923,1969,1970],{},"Shared idempotency recovers\u002Freturns the prior effect result instead of repeating it",[807,1972,1973,1974,1976],{},"No distributed lock is required for approval resolution. The conditional ",[845,1975,1587],{}," transition decides the winner.",[850,1978],{},[853,1980,1982],{"id":1981},"history","History",[807,1984,1985,1986,1988],{},"The primary page is pending work. A lightweight ",[810,1987,1982],{}," tab provides audit confidence without becoming Run Explorer.",[807,1990,1250,1991,1994,1995,1997,1998,1047,2000,1047,2002,1047,2004,2006,2007,831],{},[810,1992,1993],{},"History reads one status at a time, and it is not a merged feed."," The list takes one ",[845,1996,1582],{}," value, so four statuses need four requests and four cursors. Four ordered pages cannot merge into one. History is therefore a status selector over the same list: ",[845,1999,1439],{},[845,2001,1442],{},[845,2003,1373],{},[845,2005,1456],{},". It defaults to ",[845,2008,1439],{},[807,2010,1250,2011,1473,2014,2016],{},[810,2012,2013],{},"History reads the oldest expiry first.",[845,2015,1318],{}," ascending is the one sort key of the list, and it serves the pending queue. A newest-first audit needs a second index, and V1 adds none.",[807,2018,1250,2019,2022,2023,2026,2027,2029,2030,2033,2034,2036],{},[810,2020,2021],{},"A History row carries the list projection, and nothing more."," The list\nanswers ",[845,2024,2025],{},"ApprovalSummary",", which holds no ",[845,2028,1460],{},", no ",[845,2031,2032],{},"resolved_by"," and\nno ",[845,2035,1298],{},". A row therefore shows the same four fields the pending queue\nshows, and a reader opens the row for the decision:",[1223,2038,2039,2047,2051],{},[864,2040,1227,2041,1231,2043,1231,2045,1237],{},[845,2042,1230],{},[845,2044,1234],{},[845,2046,1020],{},[864,2048,2049,1237],{},[845,2050,1020],{},[864,2052,2053,2055],{},[845,2054,1315],{},", the request time.",[807,2057,1250,2058,2061,2062,2064,2065,2068,2069,2071],{},[810,2059,2060],{},"A resolved row announces no expiry."," It keeps the ",[845,2063,1318],{}," it was\nfiled with, and that time has usually passed. ",[845,2066,2067],{},"Expired"," on an approved row\nreads as though the approval died, which is the opposite of what happened. A\nrow the timeout resolved still reads ",[845,2070,2067],{},", because there the word is the\ndecision.",[807,2073,2074,2075,2078],{},"The detail pane answers the rest, because it reads ",[845,2076,2077],{},"ApprovalDetail",":",[1223,2080,2081,2086,2097,2101],{},[864,2082,2083,2085],{},[845,2084,1460],{},", the resolution time;",[864,2087,2088,2090,2091,2093,2094,2096],{},[845,2089,2032],{},", resolved to a name through the organization profiles the app already loads. The column is null for ",[845,2092,1373],{}," and for ",[845,2095,1456],{},", and null again after the account is deleted;",[864,2098,2099,1237],{},[845,2100,1298],{},[864,2102,2103,2105],{},[845,2104,1257],{},", the originating Run.",[807,2107,2108],{},"The detailed technical execution remains in Run Explorer. Human Review does not duplicate the span tree.",[850,2110],{},[853,2112,2114],{"id":2113},"example-flows","Example flows",[894,2116,2118],{"id":2117},"a-email-sequence-sends-to-a-new-recipient","A. Email Sequence sends to a new recipient",[1206,2120,2123],{"className":2121,"code":2122,"language":1211,"meta":1212},[1209],"Email Sequence Run\n  -> draft message\n  -> email.send proposed\n  -> Policy(action) = require_approval\n  -> persist exact send + continuation\n  -> agent.approvals\n  -> Run waiting \u002F Inngest wait\n  -> Human Review: recipient + subject + body + reason\n  -> Approve\n  -> TTL + authority + argument hash + target state rechecked\n  -> IdempotencyService reads the journal, then claims the send effect\n  -> Nylas send executes once\n  -> same Run resumes\n",[845,2124,2122],{"__ignoreMap":1212},[807,2126,2127],{},"The same Email Sequence Run may later reach another approval for a follow-up. That creates a new approval row; it is not a new Run merely because another human decision is required.",[894,2129,2131],{"id":2130},"b-signals-search-has-a-wide-admission-gate","B. Signals Search has a wide admission gate",[1206,2133,2136],{"className":2134,"code":2135,"language":1211,"meta":1212},[1209],"User asks for wide Signals Search\n  -> Front Door selects Signals Search\n  -> StartRunCommand\n  -> RunManager.start()\n  -> create Run + freeze execution snapshot\n  -> Policy(admission)\n       ├── allow -> dispatch\n       └── require_approval\n             -> approval row\n             -> Run waiting\n             -> Human Review\n             -> Approve\n             -> the Inngest wait resolves, and the same Run executes\n",[845,2137,2135],{"__ignoreMap":1212},[807,2139,2140,2141,2144],{},"The 5,000-company scope does ",[810,2142,2143],{},"not inherently"," require approval. It appears here only when the organization's current admission Policy says it does.",[807,2146,2147],{},"No Agent\u002FTool execution is spent before admission approval. The Run is created, its snapshot is frozen, the deterministic policy decision runs, and the dispatched function parks on the wait. A parked wait holds no worker and costs nothing.",[807,2149,2150,2151,2154],{},"This is separate from reviewing the resulting Organization Prospects. Prospect ",[845,2152,2153],{},"watch \u002F dismiss \u002F promote"," actions remain in Signals Search \u002F Opportunity Review.",[894,2156,2158],{"id":2157},"c-two-surfaces-race-to-resolve","C. Two surfaces race to resolve",[1206,2160,2163],{"className":2161,"code":2162,"language":1211,"meta":1212},[1209],"Slack approval button ─┐\n                       ├─► same approval id\nHuman Review page ─────┘\n                              │\n                              ▼\n                    conditional pending update\n                       ┌──────┴──────┐\n                       ▼             ▼\n                    winner       already resolved\n                       │             │\n                       ▼             ▼\n                  signal wait    return state\n",[845,2164,2162],{"__ignoreMap":1212},[807,2166,2167],{},"This guarantees one human decision transition. The eventual Tool side effect has its own Idempotency key and retry protection.",[894,2169,2171],{"id":2170},"d-worker-restarts-while-approval-waits","D. Worker restarts while approval waits",[1206,2173,2176],{"className":2174,"code":2175,"language":1211,"meta":1212},[1209],"Tool proposal\n  -> persist approval + continuation identity\n  -> Run waiting \u002F Inngest wait\n  -> worker terminates\n  -> user approves later\n  -> new worker loads Run frozen snapshot + continuation\n  -> revalidate\n  -> idempotent execution\n  -> Run continues\n",[845,2177,2175],{"__ignoreMap":1212},[807,2179,2180],{},"Human Review does not need to know which worker originally requested the approval.",[850,2182],{},[853,2184,2186],{"id":2185},"product-boundary","Product boundary",[807,2188,2189,2190,831],{},"Human Review owns ",[810,2191,2192],{},"the human decision experience",[807,2194,2195],{},"It does not own:",[1223,2197,2198,2204,2213,2219,2225,2231,2237,2243,2249],{},[864,2199,2200,2203],{},[810,2201,2202],{},"why review is required",": Policy owns the decision and reason;",[864,2205,2206,2209,2210,2212],{},[810,2207,2208],{},"Run creation or admission",": ",[845,2211,1086],{}," owns Product Run state;",[864,2214,2215,2218],{},[810,2216,2217],{},"waiting\u002Fresume",": Runtime + Inngest own durable coordination;",[864,2220,2221,2224],{},[810,2222,2223],{},"the side effect",": Tools & Integrations own execution;",[864,2226,2227,2230],{},[810,2228,2229],{},"duplicate-effect protection",": Idempotency owns it;",[864,2232,2233,2236],{},[810,2234,2235],{},"interactive channel rendering",": Channel Gateway owns web\u002FSlack\u002Fetc. presentation;",[864,2238,2239,2242],{},[810,2240,2241],{},"email transport",": Nylas\u002Femail integration owns it;",[864,2244,2245,2248],{},[810,2246,2247],{},"run debugging",": Run Explorer owns it;",[864,2250,2251,2254],{},[810,2252,2253],{},"business\u002Fprospect review state",": CRM and product workflows own it.",[807,2256,2257],{},"That boundary lets every current and future Agent\u002FWorkflow share one review experience without creating parallel approval, runtime or product-state systems.",[853,2259,2261],{"id":2260},"not-building-in-v1","Not building in V1",[807,2263,2264,2265,2267],{},"Do ",[810,2266,1075],{}," build these yet:",[1223,2269,2270,2273,2276,2279,2282,2285,2288,2291,2294,2297,2300,2303],{},[864,2271,2272],{},"bulk approval;",[864,2274,2275],{},"approval delegation \u002F reassignment;",[864,2277,2278],{},"comments or discussion threads;",[864,2280,2281],{},"editing proposed actions inside Human Review;",[864,2283,2284],{},"custom review routing;",[864,2286,2287],{},"multi-stage approval chains;",[864,2289,2290],{},"per-team queues;",[864,2292,2293],{},"SLA\u002Fescalation engine;",[864,2295,2296],{},"a second notification system;",[864,2298,2299],{},"a second approval table;",[864,2301,2302],{},"definition-version\u002Fhistory UI inside a review;",[864,2304,2305],{},"a generic manual-work\u002Ftask inbox.",[807,2307,2308],{},"If the proposed action needs to change, reject it and run the originating work again, so the new proposal receives its own authorization.",{"title":1212,"searchDepth":32,"depth":233,"links":2310},[2311,2312,2318,2322,2326,2327,2328,2329,2333,2334,2335,2336,2337,2343,2344],{"id":855,"depth":32,"text":856},{"id":891,"depth":32,"text":892,"children":2313},[2314,2315,2316],{"id":896,"depth":233,"text":897},{"id":1100,"depth":233,"text":1101},{"id":1114,"depth":233,"text":2317},"What does not belong here",{"id":1203,"depth":32,"text":1204,"children":2319},[2320,2321],{"id":1217,"depth":233,"text":1218},{"id":1265,"depth":233,"text":1266},{"id":1353,"depth":32,"text":1354,"children":2323},[2324,2325],{"id":1357,"depth":233,"text":1358},{"id":1381,"depth":233,"text":1382},{"id":1403,"depth":32,"text":1404},{"id":1534,"depth":32,"text":1535},{"id":1692,"depth":32,"text":1693},{"id":1716,"depth":32,"text":1717,"children":2330},[2331,2332],{"id":1723,"depth":233,"text":1724},{"id":1754,"depth":233,"text":1755},{"id":1775,"depth":32,"text":1776},{"id":1806,"depth":32,"text":1807},{"id":1883,"depth":32,"text":1884},{"id":1981,"depth":32,"text":1982},{"id":2113,"depth":32,"text":2114,"children":2338},[2339,2340,2341,2342],{"id":2117,"depth":233,"text":2118},{"id":2130,"depth":233,"text":2131},{"id":2157,"depth":233,"text":2158},{"id":2170,"depth":233,"text":2171},{"id":2185,"depth":32,"text":2186},{"id":2260,"depth":32,"text":2261},"md",{},true,[2349,2350,2351,2352,2353,2354,2355,2356],"engineering\u002Fsystem-design\u002Fagentic-platform","engineering\u002Fsystem-design\u002Fagentic-platform\u002Fcontract","engineering\u002Fsystem-design\u002Fagentic-platform\u002Finterfaces\u002Fsurfaces","engineering\u002Fsystem-design\u002Fagentic-platform\u002Fplanes\u002Fpolicy-and-governance","engineering\u002Fsystem-design\u002Fagentic-platform\u002Fruntime\u002Fexecution","engineering\u002Fsystem-design\u002Fagentic-platform\u002Fplanes\u002Fidempotency","engineering\u002Fsystem-design\u002Fagentic-platform\u002Fproducts\u002Femail-sequence","engineering\u002Fsystem-design\u002Fagentic-platform\u002Fproducts\u002Fsignals-search",{"title":345,"description":346},"engineering\u002Fsystem-design\u002Fagentic-platform\u002Fproducts\u002Fhuman-review",[348,255,349,198,12],"SzlukOv5EQG-yXdhWsD0ea_y_Xn7IbUkiU_8F8kiOrg",1788650195816]