Agent skill

Operator Approval Loop

by affaan-m in affaan-m/ECC

Operator approval contract with internal filing notices for agent-drafted outbound messages, hashed drafts, epoch-keyed decisions, durable delivery claims and receipts, and a pre-draft baseline gate.

MITAuto-check passed

Install Operator Approval Loop

skills CLI
$ npx skills add affaan-m/ECC --skill operator-approval-loop -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install affaan-m/ECC operator-approval-loop --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/affaan-m/ECC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/operator-approval-loop .claude/skills/operator-approval-loop && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
operator-approval-loop
GitHub stars
275k
Token cost
~3.3k tokens
SKILL.md length
1,660 words
Files
3 (incl. references)
Skills in repo
645
Repo updated
First seen
Licence
MIT

At a glance

Operator approval contract with internal filing notices for agent-drafted outbound messages, hashed drafts, epoch-keyed decisions, durable delivery claims and receipts, and a pre-draft baseline gate.

  • Works in 5 steps: Clean inputs. Strip control characters,… → Run the baseline gate (below). It may… → Hash the draft text with sha256. The… → …
  • An agent drafts messages to external counterparties and a human operator must approve
  • SKILL.md covers When to Use, How It Works, Examples and Invariants to test
  • Runs Python scripts from its folder; calls python3

What it does

Operator Approval Loop is an agent skill from affaan-m/ECC. Operator approval contract with internal filing notices for agent-drafted outbound messages, hashed drafts, epoch-keyed decisions, durable delivery claims and receipts, and a pre-draft baseline gate. Use when an agent drafts messages to external counterparties and a human operator must approve, reject, or steer each send before it leaves.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/approval_claims.py`).

The repository describes itself as: The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond. The licence is MIT.

When your agent uses it

  • An agent drafts messages to external counterparties and a human operator must approve
  • Steer each send before it leaves

Example prompts

  • “/operator-approval-loop”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Clean inputs. Strip control characters, collapse whitespace in single-line
  2. Run the baseline gate (below). It may refuse the filing.
  3. Hash the draft text with sha256. The hash prefix goes into the summary so
  4. Upsert. If an open drafted obligation already exists for the same
  5. Route the filing receipt only to a configured, verified internal ops

What it can do on your machine

Read from SKILL.md and the folder at commit ef648e0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Operator Approval Loop loads about 3.3k tokens when it runs, and up to ~8.8k if it reads all its reference files. Until then it costs about 91 tokens; SKILL.md has 1,660 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~91
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from affaan-m/ECC at commit ef648e0, republished under its MIT licence (© affaan-m). 1,660 words, ~3,281 tokens.

Download SKILL.mdSave it as .claude/skills/operator-approval-loop/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
operator-approval-loop
description
Operator approval contract with internal filing notices for agent-drafted outbound messages, hashed drafts, epoch-keyed decisions, durable delivery claims and receipts, and a pre-draft baseline gate. Use when an agent drafts messages to external counterparties and a human operator must approve, reject, or steer each send before it leaves.

Operator Approval Loop

An agent that talks to external counterparties should never send on its own judgment and should keep the operator informed internally. This skill defines the contract: every outbound draft is filed as an obligation, an operator decides on the exact text, and a delivery ledger proves what went out.

When to Use

  • An agent drafts replies to customers, suppliers, investors, or partners in a shared channel, email, or chat, and a human must approve before send.
  • You need an audit trail that links each sent message to the exact draft text, the operator who approved it, and the decision time.
  • You have seen a stale approval release a rewritten draft, or two workers deliver the same approved message twice.
  • Drafts keep re-asking counterparties for facts the ledger already holds.

How It Works

Objects
ObjectMeaning
ObligationOne thing we owe a counterparty. Status moves drafted, then approved or rejected, then sent. Carries direction, counterparty, channel, and an updated_at epoch.
DraftSidecar row holding the exact draft text, a sha256 of that text, origin coordinates (platform, channel, thread, user), and priority (P0 to P3). One per obligation, replaced on re-file.
DecisionAn operator's approve or reject, recorded with the operator id, a nonce, and the draft epoch it was made against.
Approval snapshotImmutable text, hash, epoch and destination recorded by the already-authorized decision writer. Missing snapshots cannot grant dispatch.
ClaimDurable reservation with a random token and state; at most one active claim per obligation.
DeliveryLedger row proving one send or notice for one (obligation, decision) pair.

The reference schema is in references/approval-ledger.sql.

Filing a draft
  1. Clean inputs. Strip control characters, collapse whitespace in single-line fields, and enforce length caps (draft, summary, context, counterparty). Empty or oversized fields are refused, not truncated silently.
  2. Run the baseline gate (below). It may refuse the filing.
  3. Hash the draft text with sha256. The hash prefix goes into the summary so the approval panel shows which text it is approving.
  4. Upsert. If an open drafted obligation already exists for the same (counterparty, channel), replace the draft sidecar and advance the obligation's updated_at. That advance is the epoch rotation: any decision keyed to the old epoch can no longer release the new text. Otherwise insert a new obligation with status drafted.
  5. Route the filing receipt only to a configured, verified internal ops destination. If the origin is that internal destination, acknowledge there. Never-silent means internal reporting, not an automatic external reply. Keep draft hashes, approval status, operator identity and workflow metadata out of counterparty-visible channels. Unknown or unclassified origins stay quiet; a direct message is not automatically internal.

If a verified internal destination is unavailable, retain the filing result in the internal tool result or operator surface. Never fall back to an external or unknown origin. A tool result exposed to outsiders is not an internal surface.

Filing a draft does not authorize an external response. Any policy-permitted clarifying question or neutral response is a separate outbound decision, subject to the existing mention, channel, draft-only, frozen and never constraints in counterparty-channel-discipline. It must not disclose internal approval metadata.

Baseline gate

Before any draft is filed, query the current baseline for the counterparty (a temporal ledger, contract store, or CRM):

  • Signed or delivered contract on record: refuse the filing with the evidence and a recommendation. Asking a counterparty about specs after signing is the exact failure this gate exists to stop.
  • Operator override: force_despite_signed_contract lets the filing through and stamps [BASELINE_OVERRIDE_SIGNED_CONTRACT] into the draft context.
  • Gate service unreachable: the filing proceeds and the context is stamped [BASELINE_CHECK_UNAVAILABLE]. The panel sees that the guard was off. Failures never silently disable the gate.
  • When facts are available, attach the freshest few to the context as a [BASELINE FACTS: ...] digest so the draft lands with current truth.
Deciding

The approval panel lists obligations with status drafted and direction we_owe_them. Approve or reject writes a decision row carrying the draft epoch (draft_updated_ts) and flips the obligation status in the same transaction. A decision whose epoch does not match the current updated_at is stale and must not release anything.

For an already-authorized approve decision, the same transaction inserts an immutable obligation_approval_snapshots row: decision and obligation IDs, current draft epoch, exact text and SHA-256, platform/channel/thread, and kind draft_sent. The decision writer must establish authorization before writing; the reference never authenticates an operator or manufactures a decision. Automatic approval policy is not enabled or expanded by the reference. Legacy decisions without snapshots require explicit reconciliation or a new approval; never backfill permission from the current mutable draft.

Show full SKILL.md (897 more words)Show less
Delivering

The SQLite reference is references/approval_claims.py. It grants dispatch permission but never calls transport. Use an existing local reference database initialized from the SQL fixture; the module does not apply schema or production migrations. Only a trusted decision writer may populate approval records. All writers must enable foreign keys and recursive triggers and honor the schema guards; administrative database tampering is outside this model.

  1. Discover bound approved drafts. Discovery is not permission. claim() opens its own BEGIN IMMEDIATE transaction, validates the current approved epoch, exact text, computed SHA-256 and full destination against the snapshot, and inserts a unique claim before returning its token. A conflict stops the worker before transport. Completed receipts cannot be claimed again.
  2. begin_dispatch() revalidates the binding and atomically changes claimed to dispatching using the token. Only its winning caller receives the exact draft_text and destination after commit. Never regenerate text, reread a mutable sidecar for transport, or reuse the payload for another attempt. A nested caller transaction is refused; permission cannot depend on a later caller commit. No database transaction remains open across transport.
  3. A confirmed successful result goes to complete(), which atomically records the delivery coordinate, marks the claim delivered and flips the obligation to sent. Identical completion is a no-op; conflicting coordinates fail. The receipt UNIQUE key deduplicates records, not prior external effects.
  4. Exceptions, timeouts, worker death after begin-dispatch, or failed receipt persistence leave a blocked attempt. mark_unknown() records uncertainty. Unknown claims never expire, reopen, auto-retry or allow another decision for that obligation to bypass them. A trusted caller may use reconcile() with confirmed successful coordinate and evidence; the module does not verify that evidence. An absent receipt is not proof of non-delivery.

The guarantee is one automatic dispatch attempt per approved decision, not exactly-once external delivery. A crash after begin-dispatch but before transport can leave zero sends and a held claim. Releasing an unknown outcome for a new attempt would require fencing the original executor and verifying provider semantics; this reference deliberately provides no such retry operation.

Claim stateAllowed next states
claimeddispatching or cancelled before dispatch
dispatchingdelivered or unknown
unknowndelivered through trusted reconciliation only
delivered, cancelledterminal; decision key cannot be reused

While a claim is active, database guards freeze obligation, draft and decision writes, including replacements. Snapshots and claims cannot be erased. Cancel a claimed operation with its token before re-filing; the stale token then grants nothing. After dispatch begins, hold new edits or revocation for reconciliation. This serializes changes instead of pretending to recall an in-flight operation.

Rejected decisions and legacy rows without draft sidecars/snapshots never enter this external draft-send path. Report them on the internal operator surface for manual handling. Internal receipt footers remain internal: approved by <operator> · receipt <decision_id> · draft sha256 <prefix>. Never alter already-approved external text to append workflow metadata.

Focused local validation uses temporary databases, separate connections and a simulated attempt counter, not a provider or real message: python3 -m unittest discover -s tests/skills -p 'test_approval_delivery_claims.py'. The tests require Python 3.11+ with SQLite serialization support; the reference uses only the standard library. The existing desk-pattern contract checks remain a separate compatibility check.

Time-boxed auto-approval (optional)

A draft may carry auto_send_after (epoch seconds). A sweep approves drafts whose deadline passed with no decision, recording operator auto-ttl, then delivery proceeds through the normal path. Operator actions always win: a decision flips status before the sweep sees it, and a re-file rotates the epoch and moves or clears the deadline. The sweep re-checks status and epoch inside the write transaction so a race resolves as a no-op. Drafts without a deadline stay hard-gated forever.

Signal linkage

A draft can name the inbound obligation it answers (signal_obligation_id). This is the only truthful link for latency measurement (inbound signal to drafted response) and lets the SLA scan treat that inbound item as answered. Reject the filing if the referenced row does not exist.

Examples

File a draft
text
file_request(
  draft="Thanks, we can hold the slot until Friday. Which start date works?",
  counterparty="acme-supplier",
  context="reply to delivery window question",
  origin_platform="slack", origin_channel="#acme-shared",
  origin_thread="1712345678.000100", priority="P1",
  signal_obligation_id=412)
-> {obligation_id: 431, draft_sha256: "9f2c...", refiled: false}

The configured, verified internal ops destination sees: Draft filed for approval (P1, sha 9f2c8a1b). Waiting on operator. The counterparty-visible origin channel receives no filing notice. If no verified internal destination is available, the receipt stays in the internal tool result or operator surface, with no external fallback.

Re-file after a steer

The operator asks for a shorter draft. Filing again for the same (counterparty, channel) returns refiled: true, the sidecar text and hash change, and updated_at advances. An approve clicked on the old panel row carries the old epoch and is ignored.

Gate refusal
text
DeskApprovalError: baseline gate refused this draft: the ledger shows a
signed contract for 'acme-supplier'. Evidence: master agreement executed
2026-08-14. Recommendation: do not ask. Re-file with
force_despite_signed_contract=true if this is genuinely a new thread.
text
Confirmed for Friday, start date 2026-09-08.
approved by operator-a · receipt 118 · draft sha256 9f2c8a1b2d3e4f50

Invariants to test

  • Filing receipts go only to configured, verified internal ops; the origin receives one only when it is that verified internal destination.
  • An unknown origin stays quiet. An unavailable internal destination uses the internal tool result or operator surface, with no external fallback.
  • Same (counterparty, channel) filed twice yields one obligation, two epochs.
  • A decision with a stale epoch never results in a delivery row.
  • Two concurrent claimants yield one dispatch permission; losers never attempt transport.
  • Unknown outcomes and failed receipt persistence never enable an automatic retry.
  • Successful completion records the receipt and sent status in one transaction.
  • An altered epoch, text, hash or destination cannot acquire or begin a claim.
  • Active claims block re-file; only pre-dispatch cancellation can release that hold.
  • Gate unavailable stamps the marker; gate signed refuses without force.
  • Auto-ttl never fires against text the operator has since re-filed.

© affaan-m, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/operator-approval-loop of affaan-m/ECC.

  • SKILL.md
  • references/approval-ledger.sql
  • references/approval_claims.py

Open the folder on GitHubat commit ef648e0

Compare with similar skills

Operator Approval Loop next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Operator Approval Loop compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Operator Approval Loop this skillaffaan-m/ECC275k—~3.3kAutomated safety check: PassMIT
Business Operations Skillsalirezarezvani/claude-skills28k—~2.3kAutomated safety check: PassMIT
Internal Comms Anthropicsickn33/agentic-awesome-skills47k1 repos~702Automated safety check: PassApache-2.0
Internal Commsalirezarezvani/claude-skills28k—~3.4kAutomated safety check: PassMIT
Draftanthropics/claude-for-legal9.6k3 repos~2.4kAutomated safety check: PassApache-2.0
Internal Communicationsickn33/agentic-awesome-skills47k1 repos~3.4kAutomated safety check: PassMIT

Similar skills

  • Business Operations Skills

    alirezarezvani/claude-skills

    A skill your agent uses when running, diagnosing, or designing internal business operations — process documentation, vendor SLAs, capacity planning, internal comms, SOP/runbook authoring…

    28k GitHub stars~2.3k tokensUpdated 1 mo ago
    Business, Finance & HRAuto-check passed
  • Internal Comms Anthropic

    sickn33/agentic-awesome-skills

    Compatibility alias for internal-comms: draft status updates, newsletters and FAQs from approved sources.

    47k GitHub starsUsed in 1 repo~702 tokens
    Writing & ContentAuto-check passed
  • Internal Comms

    alirezarezvani/claude-skills

    A skill your agent uses when a Head of People Ops, BizOps lead, or Internal Communications owner needs to draft and sequence an internal-only change-management communication — a re-org announcement…

    28k GitHub stars~3.4k tokensUpdated 1 mo ago
    Writing & ContentAuto-check passed
  • Draft

    anthropics/claude-for-legal

    Official

    First draft of a common clinic document — practice-area templates (asylum applications, eviction answers, protective order petitions, demand letters), jurisdiction-aware formatting, explicitly a…

    9.6k GitHub starsUsed in 3 repos~2.4k tokens
    Legal & ComplianceAuto-check passed
  • Internal Communication

    sickn33/agentic-awesome-skills

    Internal communication log: title, type, date, department, host and attendees, agenda, action items, follow-up date, meeting link and delivery status.

    47k GitHub starsUsed in 1 repo~3.4k tokens
    Writing & ContentAuto-check passed
  • File Organizer

    davila7/claude-code-templates

    Intelligently organizes files and folders by understanding context, finding duplicates, and suggesting better organizational structures.

    32k GitHub starsUsed in 7 repos~1.6k tokens
    Productivity & AutomationAuto-check passed

More from affaan-m/ECC

All 645 skills in this repo
  • Videodb

    affaan-m/ECC

    Ingest, index, search, edit, and monitor video and audio with the VideoDB Python SDK — upload from files, URLs, or RTSP feeds, build spoken and scene indexes with timestamped search and playable…

    275k GitHub starsUsed in 3 repos~3.5k tokens
    Auto-check: notes
  • Rules Distillation

    affaan-m/ECC

    Scans installed skills for principles that recur across them and proposes rule-file changes: append, revise, add a section, create a file or leave as covered.

    275k GitHub starsUsed in 2 repos~2.3k tokens
    Auto-check passed
  • Builds DRAFT counterparty agreements from one markdown template and a small JSON spec per party, with clauses picked by the party's role.

    275k GitHub stars~2.9k tokensUpdated 3 days ago
    Auto-check passed
  • Measures whether agents actually follow a skill, rule or agent definition by generating scenarios at three strictness levels and scoring tool-call traces.

    275k GitHub starsUsed in 1 repo~623 tokens
    Auto-check passed
  • Instinct-based learning system that observes sessions via hooks, creates atomic instincts with confidence scoring, and evolves them into skills/commands/agents.

    275k GitHub stars~3.5k tokensUpdated 3 days ago
    Auto-check passed
  • Adds one optional external Codex critique that tries to break a council's decision draft, sent to OpenAI only after you consent.

    275k GitHub stars~1.5k tokensUpdated 3 days ago
    Auto-check passed

Questions about Operator Approval Loop

What does Operator Approval Loop do?

Operator approval contract with internal filing notices for agent-drafted outbound messages, hashed drafts, epoch-keyed decisions, durable delivery claims and receipts, and a pre-draft baseline gate. Operator Approval Loop is an agent skill from affaan-m/ECC. Operator approval contract with internal filing notices for agent-drafted outbound messages, hashed drafts, epoch-keyed decisions, durable delivery claims and receipts, and a pre-draft baseline gate.

When should I use Operator Approval Loop?

Operator Approval Loop fits situations like: an agent drafts messages to external counterparties and a human operator must approve; steer each send before it leaves.

How do I install Operator Approval Loop in Claude Code?

Run `npx skills add affaan-m/ECC --skill operator-approval-loop -a claude-code`. Or copy the skill folder (skills/operator-approval-loop in affaan-m/ECC) into .claude/skills/operator-approval-loop in your project. Claude Code loads it when a task matches its description.

How do I install Operator Approval Loop in Codex?

Run `npx skills add affaan-m/ECC --skill operator-approval-loop -a codex`. Or copy the skill folder (skills/operator-approval-loop in affaan-m/ECC) into .agents/skills/operator-approval-loop in your project. Codex loads it when a task matches its description.

Can I use Operator Approval Loop in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add affaan-m/ECC --skill operator-approval-loop -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/operator-approval-loop, .gemini/skills/operator-approval-loop, .github/skills/operator-approval-loop and .opencode/skills/operator-approval-loop in your project.

What does Operator Approval Loop need to run?

Going by SKILL.md and its folder, Operator Approval Loop needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Operator Approval Loop access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Operator Approval Loop safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Operator Approval Loop use?

Operator Approval Loop is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Operator Approval Loop use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.5k tokens, read only when the agent opens those files.

What are the alternatives to Operator Approval Loop?

Skills that share tags, products or a category with Operator Approval Loop: Business Operations Skills (alirezarezvani/claude-skills, 28k stars), Internal Comms Anthropic (sickn33/agentic-awesome-skills, 47k stars), Internal Comms (alirezarezvani/claude-skills, 28k stars) and Draft (anthropics/claude-for-legal, 9.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Operator Approval Loop?

affaan-m (a GitHub user) maintains it in affaan-m/ECC, which has 275,023 GitHub stars. The repository holds 645 skills in this directory. The repository was last updated on October 5, 2026.

Source: affaan-m/ECC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.