Agents propose. Humans decide.
An agent can submit. It cannot approve, deny, read another's request or touch a pending one. Not blocked — absent. The buttons don't exist for it.
humanqueue is the private lane between an agent's intention and the real world. Intentions go in as proposals. Nothing comes out without a decision — yours, or a local AI that answers only to rules you set.
One decision, start to finish
The agent can't press approve on defined actions — the button doesn't exist for it. Watch a real-shaped proposal move through the lane.
How the lane is chosen
A small AI runs on your machine. It reads your policy and decides one thing: does this need a human? It never sees a secret and never talks to anyone it should not.
Default: restricted. Every lane starts closed and is opened on purpose.
What it stands for
An agent can submit. It cannot approve, deny, read another's request or touch a pending one. Not blocked — absent. The buttons don't exist for it.
A local private AI reads your policy and decides what needs you. It cannot be prompted, phoned or persuaded.
Rules only get tighter. You can add a restriction; nothing — not a setting, a prompt, or an agent — can loosen one.
Keys and passwords enter once and are never seen again. Not by an agent. Not by you. Can't leak, won't leak.
Every proposal, edit, route and decision — who, when, where — correlated and kept. Grants are audited and revocable.
There is no code path around the gate. It isn't a switch someone could flip. It's the structure of the thing.
Permissions flow down. Approvals flow up. Your queue, your team's queue, and the one above it.
Everything is written down
Who decided, when, on what — and which lane it took. Illustrative entries; the real ledger lives on your machine.
Where decisions surface
Proposals wait in humanqueue and surface in MoltenRock Connect — reviewed, edited if you like, and approved with a touch. Part of the MoltenRock ecosystem: private, local, yours.