Home/Use Cases/AI Governance
AI Governance

Your agents can act.Now put a human in the loop.

AI agent proof-of-work is part of the Aptiwise governance-of-work fabric. Gated MCP puts a human approval step in front of any AI agent's sensitive tool calls — including third-party MCP servers you didn't build — with the same immutable audit trail as every human approval.

The Problem

Agents already have write access. Governance hasn't caught up.

Coding & ops agents can already delete things

Autonomous agents given file, repo, or infrastructure tool access can create, overwrite, or delete — with no human checkpoint before the action executes.

Every MCP server has its own auth model

You can't bolt one governance layer onto every agent framework and third-party MCP server your teams adopt — each one ships with a different, or no, permission story.

No audit trail for what an agent actually did

Human approvals get logged. Agent tool calls usually don't — so when something goes wrong, there's no timestamped record of what was requested, by what, or who signed off.

How Aptiwise Helps

Gated MCP: a human checkpoint for any agent

Sensitive tool calls pend for a human decision before they execute — routed through the exact same approval engine, audit log, and notification system as every other Aptiwise workflow.

Gated MCP

An agent requests approval. A human decides. No login required.

When an agent calls a sensitive tool, the call pends behind a human-in-the-loop approval gate. The approver gets an email with a one-click approve or reject link — the agent's call only proceeds once a human signs off.

  • Email approve/reject, no login required
  • The agent's tool call only executes after approval
  • Escalate to a parallel approval group for higher-risk actions
Animated demo
Animated demo
MCP Server Wrapping

Wrap any MCP server — including ones you didn't build

One command spawns any existing stdio MCP server as a child process and re-exposes it with sensitive tools gated behind human approval — no changes to the upstream server, no per-server integration work.

approvalml -- npx -y @modelcontextprotocol/server-github
Zero-Config Classification

Read-only tools pass through. Sensitive ones pend for approval.

Every tool the agent can see gets classified automatically — by name (get_/list_ vs create_/delete_) and by the MCP tool's own annotations. Any disagreement between the two defaults to a gate, not a silent allow.

  • No manual allow-list to maintain for read-only tools
  • Ambiguity always pends — never silently denied or allowed
  • Override with explicit glob rules for tighter control
Animated demo
Animated demo
Notifications & Audit

The same audit trail as every human approval

A gated agent call isn't a bolt-on feature — it runs through the identical approval engine as any other Aptiwise workflow. Approval requests can also notify Slack or any webhook channel alongside email, so the right team sees it the moment it's raised.

  • Every agent approval hits the same hash-chained audit log
  • Slack & webhook notifications alongside email
  • Start self-hosted, move to Aptiwise without rewriting a workflow

Common Workflows

Where teams put agents on a leash

Coding Agent Guardrails

Gate destructive git, file, or deploy operations behind human approval.

Infra & DevOps Agent Gates

Agent-triggered cloud changes require sign-off before they execute.

Data & Finance Agent Oversight

Agent-initiated payments, exports, or record changes need a human sign-off.

Third-Party MCP Server Gating

Wrap any external MCP server with approval gates, no code changes required.

Governance of Work

AI agent governance is one layer of the Aptiwise fabric. The same engine powers Access Governance, procurement, O2C, and compliance workflows — all on one proof-of-work ledger.

Access Governance

AI Governance

Ready to put your
agents on a leash?

Book a 30-minute demo. We'll walk through wrapping one of your existing MCP servers or agent tool calls with a live approval gate.