Approve before, not after.
When the agent wants to run a gated tool call, it stops and the message lands in your chat with Approve and Deny. Your tap is recorded in the hash-chained log. Calls that hit a built-in deny rule or a keystone path are refused before anyone is asked.
How a gated call reaches you
-
The agent asks for a tool call.
A shell command, a file write, an MCP call.
-
Warding's own gate checks it first.
Keystone paths, the built-in deny rules and POLICY ∩ PROFILE. A refusal here is final and is logged; nobody is asked.
-
Anything left that needs approval waits for you.
With tool approval set to Interactive, the call is held and the message goes to the chat the session is running in. The default is Auto: a fresh install runs whatever the gate allows without asking, so switch it in the dashboard's approval picker or set agent.approval_mode to interactive.
-
You tap Approve or Deny.
The call runs or it doesn't, and the decision is appended to the audit log.
claude wants to run git push origin fix/auth-flake in ~/app
Your tap is real; the chat is simulated. Nothing here auto-approves.
Simulated demo: the buttons are real, the chat is not. Telegram approvals on Claude Code are being verified; see the dated log.
Built-in denies never ask
A deny rule is not a question. git push origin main, rm -rf ~, curl … | sh or a read of ~/.aws/credentials is refused at the gate, logged, and never sent to your phone. You only get asked about what the rules allow. What is enforced where, and what fails open: /security/#scope.
Which chat apps can approve
Five apps with buttons. One typed. Four chat-only. Every one of the ten can chat with the agent; not every one can approve.
| App | Approvals | How it works |
|---|---|---|
| Slack | Buttons | Approve / Deny buttons on the message. |
| Discord | Buttons | Approve / Deny buttons on the message. |
| Telegram | Buttons | Approve / Deny buttons on the message. |
| Teams | Buttons | Approve / Deny buttons on the message. |
| Webex | Buttons | Approve / Deny buttons on the message. |
| Typed reply | A numbered question: reply 1 to approve, 2 to deny, 3 to trust the session. No reply within five minutes denies. Only the linked account can answer. | |
| iMessage | Chat only | Chat works. A gated call cannot be approved from this app today. Planned, not started: typed replies. |
| Chat only | Chat works. A gated call cannot be approved from this app today. Nothing scheduled; the list decides. | |
| WeCom | Chat only | Chat works. A gated call cannot be approved from this app today. Planned, not started: buttons. |
| Feishu | Chat only | Chat works. A gated call cannot be approved from this app today. Planned, not started: buttons. |
Setup for each app: Channels
Want approvals in a chat-only app?
None of this is built yet. Each list tells us which app to do first.
iMessage
Chat onlyPlanned, not started: typed replies.
Release notifications are not available yet. Read the source publication status.
Nothing scheduled; the list decides.
Release notifications are not available yet. Read the source publication status.
WeCom
Chat onlyPlanned, not started: buttons.
Release notifications are not available yet. Read the source publication status.
Feishu
Chat onlyPlanned, not started: buttons.
Release notifications are not available yet. Read the source publication status.
Auto-approve, and what it does not lift
Tool approval defaults to Auto: nothing is held for you until you choose Interactive, per session in the dashboard's approval picker or for every session with agent.approval_mode: interactive. The /yolo grant, in a chat that supports it, lifts the question again for the whole process with one expiry, not per channel. Either way it skips the question, not the gate: keystone paths, the policy ceiling and the deny rules still refuse.
In development Allow until 07:00 is in development: a grant for one command that expires at dawn, then asks again.
Review the local beta.
Apache-2.0 source publication is pending. Read the setup notes and verification limits.
Source publication pending
Public source, install commands and downloads are not available yet. A clean install and live workflow are not yet verified.