Agent skill

Manage Approvals

by ucsandman in ucsandman/DashClaw

Human-in-the-loop approval workflows for governed agent actions

MITAuto-check passedAgent Workflows

Install Manage Approvals

skills CLI
$ npx skills add ucsandman/DashClaw --skill manage-approvals -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ucsandman/DashClaw manage-approvals --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ucsandman/DashClaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/dashclaw-agent/manage-approvals .claude/skills/manage-approvals && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
manage-approvals
GitHub stars
311
Token cost
~1.2k tokens
SKILL.md length
332 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
MIT

At a glance

Human-in-the-loop approval workflows for governed agent actions

  • Works in 4 steps: Dashboard (Web UI) → CLI (Terminal) → SDK Polling (Agent-Side) → …
  • Tasks that involve Human-in-the-loop approvals
  • SKILL.md covers When Approvals Trigger, Approval Channels, Full Approval Flow Architecture and Claude Code Hook Approval Flow, plus 2 more sections
  • Calls curl; needs DASHCLAW_API_KEY

What it does

Manage Approvals is an agent skill from ucsandman/DashClaw. Human-in-the-loop approval workflows for governed agent actions

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering Human-in-the-loop approvals and Building AI agents. It works with Model Context Protocol. The repository describes itself as: Remote approvals, policy checks, and execution evidence for unattended AI agents. The licence is MIT.

When your agent uses it

  • Tasks that involve Human-in-the-loop approvals
  • Tasks that involve Building AI agents

Example prompts

  • “/manage-approvals”

Requirements

  • Python 3
  • A credential in DASHCLAW_API_KEY

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Dashboard (Web UI)
  2. CLI (Terminal)
  3. SDK Polling (Agent-Side)
  4. API Direct

What it can do on your machine

Read from SKILL.md and the folder at commit 704824d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DASHCLAW_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Manage Approvals loads about 1.2k tokens when it runs. Until then it costs about 20 tokens; SKILL.md has 332 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~20
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ucsandman/DashClaw at commit 704824d, republished under its MIT licence (© ucsandman). 332 words, ~1,182 tokens.

Download SKILL.mdSave it as .claude/skills/manage-approvals/SKILL.md (or your agent's skills folder).
name
manage-approvals
description
Human-in-the-loop approval workflows for governed agent actions
license
MIT
metadata.author
ucsandman
metadata.version
1.0.0
metadata.category
operations

Manage Approvals

DashClaw's HITL (Human-in-the-Loop) system lets operators approve or deny agent actions before they execute. Three channels: dashboard, CLI, and SDK polling.

When Approvals Trigger

Approvals are triggered when:

  1. A guard policy returns require_approval
  2. An action's risk score exceeds the org's approval threshold
  3. The action touches systems flagged for mandatory review

The action enters pending_approval status and the agent waits.

Approval Channels

1. Dashboard (Web UI)

Navigate to the DashClaw dashboard → Approvals or Decisions view. Pending approvals show with:

  • Action type and declared goal
  • Agent ID
  • Risk score (color-coded)
  • Systems touched
  • Replay link for full decision context

Click Approve or Deny with optional reasoning.

2. CLI (Terminal)
bash
# Interactive inbox — live updates via SSE
dashclaw approvals

# Direct approve/deny
dashclaw approve act_abc123 --reason "Reviewed deployment plan"
dashclaw deny act_abc123 --reason "Missing staging verification"

The interactive inbox (dashclaw approvals) uses SSE for real-time push notifications. New approval requests appear immediately without polling.

Keyboard shortcuts:

  • A — Approve selected
  • D — Deny selected
  • R — Refresh
  • O — Open replay in browser
  • Q — Quit
3. SDK Polling (Agent-Side)
javascript
// Agent waits for approval after guard returns require_approval
try {
  await claw.waitForApproval(decision.action_id, {
    timeout: 300000  // 5 minutes
  });
  console.log('Approved — proceeding');
} catch (err) {
  if (err instanceof ApprovalDeniedError) {
    console.log('Denied:', err.message);
    return;
  }
  throw err;
}
python
try:
    claw.wait_for_approval(decision["action_id"], timeout=300000)
    print("Approved — proceeding")
except ApprovalDeniedError as e:
    print(f"Denied: {e}")
    return
4. API Direct
bash
# Approve
curl -X POST "$DASHCLAW_BASE_URL/api/approvals/act_abc123" \
  -H "x-api-key: $DASHCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"decision": "approved", "reasoning": "Reviewed and safe"}'

# Deny
curl -X POST "$DASHCLAW_BASE_URL/api/approvals/act_abc123" \
  -H "x-api-key: $DASHCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"decision": "denied", "reasoning": "Risk too high"}'

Full Approval Flow Architecture

Agent calls claw.guard({ action_type, risk_score, ... })
        ↓
Guard evaluates policies → returns require_approval
        ↓
Action created with status: pending_approval
        ↓
Agent calls claw.waitForApproval(actionId)
   (polls or uses SSE stream)
        ↓                              ↓
Operator sees in dashboard/CLI    Operator opens CLI inbox
        ↓                              ↓
Reviews: goal, risk, systems      Uses A/D keys or direct command
        ↓                              ↓
        └──────── Decision ────────────┘
                    ↓
           approved → agent continues
           denied → ApprovalDeniedError thrown
           timeout → blocked (enforce) or allowed (observe)

Claude Code Hook Approval Flow

When using the pretool/posttool hooks with Claude Code:

  1. Claude Code calls a tool (e.g., Bash: git push origin main)
  2. Pretool classifies: action_type=deploy, risk=80, reversible=false
  3. Pretool calls POST /api/guard → gets require_approval
  4. Pretool creates action with pending_approval status
  5. Pretool polls for approval (30-second timeout)
  6. Operator approves via dashclaw approvals in another terminal
  7. Pretool receives approval → exits 0 → tool executes
  8. Posttool records outcome → PATCH /api/actions/:id

If approval times out or is denied, pretool exits 2 (enforce mode) and the tool is blocked.

Listing Pending Approvals

javascript
// SDK
const pending = await claw.getPendingApprovals({ limit: 50, offset: 0 });

// API
// GET /api/actions?status=pending_approval&limit=50

Approval Best Practices

  • Use SSE for real-time: The CLI inbox uses SSE streaming so approvals appear instantly
  • Set reasonable timeouts: 5 minutes for interactive workflows, 30 seconds for hooks
  • Include reasoning: Always provide reasoning when approving/denying — it's part of the audit trail
  • Don't skip in production: HITL gates exist because the action is high-risk. Bypassing defeats the purpose.
  • Use the replay link: Every action has a replay URL showing the full decision chain — use it to review context before approving

© ucsandman, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/dashclaw-agent/manage-approvals of ucsandman/DashClaw.

Open the folder on GitHubat commit 704824d

Compare with similar skills

Manage Approvals next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Manage Approvals compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Manage Approvals this skillucsandman/DashClaw311—~1.2kAutomated safety check: PassMIT
Agent Self-Customizationnanocoai/nanoclaw31k—~1.5kAutomated safety check: NotesMIT
Dive Into LangGraphluochang212/dive-into-langgraph457—~837Automated safety check: NotesCustom licence
Ask User QuestionMemTensor/MemOS12k—~1kAutomated safety check: PassApache-2.0
Agentmemory Forgetrohitg00/agentmemory29k—~612Automated safety check: PassApache-2.0
Adk Agent Buildergoogle/adk-python22k—~879Automated safety check: PassApache-2.0

Similar skills

  • Agent Self-Customization

    nanocoai/nanoclaw

    A decision tree for an agent changing its own setup: edit memory directly, request approval for packages and MCP servers, and delegate code edits to a builder agent.

    31k GitHub stars~1.5k tokensUpdated today
    Agent WorkflowsAuto-check: notes
  • Dive Into LangGraph

    luochang212/dive-into-langgraph

    A Chinese-language guide and reference for building agents with LangGraph 1.0, from a first ReAct agent through middleware, memory, MCP, RAG and web search.

    457 GitHub stars~837 tokensUpdated 29 days ago
    AI & LLM EngineeringAuto-check: notes
  • Ask User Question

    MemTensor/MemOS

    Shows a question as a modal in the interface to clarify a task, collect a preference or get approval, since the user cannot see terminal output.

    12k GitHub stars~1k tokensUpdated 2 days ago
    Agent WorkflowsAuto-check passed
  • Agentmemory Forget

    rohitg00/agentmemory

    Deletes chosen memories from agentmemory only after showing the matches and getting an explicit yes, for privacy requests and cleanup of outdated notes.

    29k GitHub stars~612 tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Adk Agent Builder

    google/adk-python

    Official

    Builds ADK (Agent Development Kit) Python agents: LLM agents with tools, graph workflows of function and agent nodes, conditional routing, fan-out and join, schema-validated delegation between…

    22k GitHub stars~879 tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Linggen

    linggen/linggen-memory

    Linggen — durable cross-host memory plus browser control, over two local MCP servers: ling-mem for memory, the Linggen engine for browser, X and agents.

    109 GitHub stars~8.6k tokensUpdated 5 days ago
    Agent WorkflowsAuto-check: notes

More from ucsandman/DashClaw

All 13 skills in this repo
  • Dashclaw Governance

    ucsandman/DashClaw

    Governance behavior for AI agents governed by DashClaw. An agent skill from ucsandman/DashClaw.

    311 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Dashclaw Ship

    ucsandman/DashClaw

    The single command that gets a DashClaw change ON MAIN AND LIVE — it resolves everything blocking production, never defers, and never hands back a checklist.

    311 GitHub stars~7.2k tokensUpdated yesterday
    Auto-check passed
  • Repro

    ucsandman/DashClaw

    Turn a bug symptom into a structured, reproducible bug report — summary, environment, exact repro steps, actual vs expected, and evidence (logs, error text, failing route/test) — and then optionally…

    311 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Muse Governance

    ucsandman/DashClaw

    Governance behavior for Muse agents governed by DashClaw. An agent skill from ucsandman/DashClaw.

    311 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Build Dashclaw

    ucsandman/DashClaw

    Contribute to the DashClaw codebase — architecture, scaffolding, tests, CI

    311 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Compliance Drift Evals

    ucsandman/DashClaw

    Set up compliance exports, drift detection, evaluations, scoring, and learning analytics

    311 GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Manage Approvals

What does Manage Approvals do?

Human-in-the-loop approval workflows for governed agent actions. Manage Approvals is an agent skill from ucsandman/DashClaw.

When should I use Manage Approvals?

Manage Approvals fits situations like: tasks that involve Human-in-the-loop approvals; tasks that involve Building AI agents.

How do I install Manage Approvals in Claude Code?

Run `npx skills add ucsandman/DashClaw --skill manage-approvals -a claude-code`. Or copy the skill folder (.claude/skills/dashclaw-agent/manage-approvals in ucsandman/DashClaw) into .claude/skills/manage-approvals in your project. Claude Code loads it when a task matches its description.

How do I install Manage Approvals in Codex?

Run `npx skills add ucsandman/DashClaw --skill manage-approvals -a codex`. Or copy the skill folder (.claude/skills/dashclaw-agent/manage-approvals in ucsandman/DashClaw) into .agents/skills/manage-approvals in your project. Codex loads it when a task matches its description.

Can I use Manage Approvals in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ucsandman/DashClaw --skill manage-approvals -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/manage-approvals, .gemini/skills/manage-approvals, .github/skills/manage-approvals and .opencode/skills/manage-approvals in your project.

What does Manage Approvals need to run?

Going by SKILL.md and its folder, Manage Approvals needs the command-line tools its instructions call (curl) and credentials named DASHCLAW_API_KEY. Our summary lists: Python 3; A credential in DASHCLAW_API_KEY.

Does Manage Approvals access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Manage Approvals safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Manage Approvals use?

Manage Approvals is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Manage Approvals use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Manage Approvals?

Skills that share tags, products or a category with Manage Approvals: Agent Self-Customization (nanocoai/nanoclaw, 31k stars), Dive Into LangGraph (luochang212/dive-into-langgraph, 457 stars), Ask User Question (MemTensor/MemOS, 12k stars) and Agentmemory Forget (rohitg00/agentmemory, 29k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Manage Approvals?

ucsandman (a GitHub user) maintains it in ucsandman/DashClaw, which has 311 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 10, 2026.

Source: ucsandman/DashClaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.