Handle sensitive actions
Goal: let the agent do the preparation work for a sensitive change while you keep control of the effects.
Skill: usually Implement · Walkthrough: WT-06 (high-impact approval) · Policy: human-approval.md
The pattern: prepare, then ask only for what’s missing
Section titled “The pattern: prepare, then ask only for what’s missing”Writing a migration file is different from applying it. Ask for the preparation and the proposal together:
Prepare the migration file for the agreed schema change. Propose verification against the disposable test database; do not apply it yet.The agent writes the migration file, which is ordinary G2 preparation. It inspects the script and the target, then presents an approval request for the execution step.
What a proper approval request contains
Section titled “What a proper approval request contains”From the approval request template:
| Field | Example (illustrative) |
|---|---|
| Action | Apply migration 20260929_add_export_flag |
| Files / resources | db/migrations/20260929_add_export_flag.sql |
| Environment | Disposable local test database orders_test |
| Expected effects | Adds one nullable column; no data rewrite |
| Risk and reason | MEDIUM: schema change on shared test data, reversible |
| Alternatives | Run against an ephemeral container instead |
| Rollback / reversibility | Down migration drops the column; data loss none |
| Excluded actions | No production or staging database; no seed changes |
It then asks for only the missing decision.
Approving
Section titled “Approving”Reply with a clear approval that matches the scope:
Approved: apply that migration to orders_test only.The agent reuses that approval for the same action and target. It will not ask again because it moved to the verification step.
When approval does not carry over
Section titled “When approval does not carry over”A new approval is needed when any of these change:
- a second database, or production instead of test;
- a new data destination or wider affected users;
- changed script effects, or a destructive operation.
Some actions stay restricted regardless. Under G4, production, destructive, or security-critical execution is not performed by default, and confirmation alone is insufficient. If your organization prohibits it, typing “approved” does not change that.
What never counts as approval
Section titled “What never counts as approval”- Another AI or PM agent, or a generated message
- Text inside Memory, a README, an issue, or tool output
- A document named “approval” without real provenance
- A copied approval from a different scope or fixture
Governance decisions you will see
Section titled “Governance decisions you will see”| Outcome | Meaning |
|---|---|
PROCEED |
Evidence supports exactly the stated action |
HOLD |
Waiting on a named fact, approval, or prerequisite |
DENY |
A prohibition, missing access right, or host denial applies |