Written by the Empire Edge team.
Approval Gate wraps our internal owner-gate (og) as a customer-facing API. The
flow is a direct 1:1 match to our own CLI: og request files the action, og
grant signs it off (owner-token gated, sealed passphrase, no AI/service self-approval by
design), and og exec executes it — only after the grant exists.
Every step appends to a hash-chained JSONL audit log, tamper-evident by construction. This is the same log our own fleet governance runs on today, with 9,000+ real records — not a demo-only mechanism.
It's built for regulated-industry workflows that legally require a human sign-off first: AML SAR triage, KYC review, claim-denial appeal, and privileged agent actions like git.push/payments/content.publish/dns.write.