← Home

Decision Layer

Approval Queue

This is the Command Center approval display for high-tier voice/app actions. It is approval-gated: Tier 2–4 work does not get blanket access, and every approval is scoped by capability, risk tier, and request fingerprint.

Pending execution approvals

Use Allow Once, Allow Session, Allow Always, or Decline. “Allow Always” is not unrestricted; it remains fingerprint-bound.

0 pending

No pending execution approval tickets.

Active approved grants

No active approved grants.

Resolved execution tickets

4685529f-bc80-48c4-b9a4-73c6393ec682

expired
Capability
bounded_diagnostic_terminal
Tier
3
Grant
once
Requested by
command-center-voice
Created
7/28/2026, 1:39:49 PM
Expires
7/28/2026, 1:49:49 PM
Command summary
type: terminal
profile:
toolsets:
command: date
path:
filename:

660ff1b2-6eec-4016-b8f2-86cd39cb6893

expired
Capability
bounded_diagnostic_terminal
Tier
3
Grant
once
Requested by
command-center-voice
Created
7/28/2026, 1:38:47 PM
Expires
7/28/2026, 1:48:47 PM
Command summary
type: terminal
profile:
toolsets:
command: date
path:
filename:

0520bf48-1e08-4b90-b5c5-389ecb1414d1

expired
Capability
bounded_diagnostic_terminal
Tier
3
Grant
once
Requested by
command-center-voice
Created
7/28/2026, 1:37:52 PM
Expires
7/28/2026, 1:47:52 PM
Command summary
type: terminal
profile:
toolsets:
command: date
path:
filename:

7598470e-3189-450e-aa6a-23dd29d7d5bc

consumed
Capability
bounded_diagnostic_terminal
Tier
3
Grant
once
Requested by
command-center-voice
Created
7/11/2026, 3:19:46 PM
Expires
7/11/2026, 3:30:50 PM
Command summary
type: terminal
profile:
toolsets:
command: date
path:
filename:

d72a33b8-a0af-4f5d-91cb-74cf93f3a5f8

consumed
Capability
bounded_diagnostic_terminal
Tier
3
Grant
once
Requested by
command-center-voice
Created
7/11/2026, 3:17:31 PM
Expires
7/11/2026, 3:29:25 PM
Command summary
type: terminal
profile:
toolsets:
command: date
path:
filename:

112f4f18-f9f7-435c-8cfa-360200c6d88f

consumed
Capability
bounded_diagnostic_terminal
Tier
3
Grant
once
Requested by
command-center-voice
Created
7/11/2026, 3:16:13 PM
Expires
7/11/2026, 3:26:51 PM
Command summary
type: terminal
profile:
toolsets:
command: date
path:
filename:

ac6a52f5-fbdb-44f8-8f3d-ac842027941c

expired
Capability
bounded_diagnostic_terminal
Tier
3
Grant
once
Requested by
command-center-voice
Created
7/11/2026, 3:15:08 PM
Expires
7/11/2026, 3:25:08 PM
Command summary
type: terminal
profile:
toolsets:
command: date
path:
filename:

4f4bafcc-e837-47d6-a302-ce79e979bf07

consumed
Capability
bounded_diagnostic_terminal
Tier
3
Grant
once
Requested by
command-center-voice-runtime-test
Created
7/9/2026, 10:22:41 AM
Expires
7/9/2026, 10:32:41 AM
Command summary
type: terminal
profile:
toolsets:
command: printf jarvis-runtime-ok
path:
filename:

Bridge-note approval queue

Legacy local queue from /opt/data/agent-bridge/approval_queue.md; retained for operator visibility and migration compatibility.

2026-07-25 — D.E.V. proactive-loop context-budget repair

- ⚠️ APPROVAL NEEDED
- Title: Compact the D.E.V. proactive improvement cron payload after confirmed context overflow
- Proposed action: Approve a scoped edit to cron job `3e21e66c188b` only: replace its repeated 8,319-character prompt with the compact 1,631-character instruction in `/opt/data/agent-bridge/recurring-jobs/context-compaction-preview-latest.md`, remove the 99,195-character `personal-ai-operating-system` umbrella skill attachment, retain the `hermes-agent` skill and minimum terminal/file/session-search/skills toolsets, preserve Slack delivery and the every-180-minute schedule, then verify the cron listing, rerun `/opt/data/profiles/dev/scripts/cron-context-budget-audit.py`, and wait for one real successful scheduled run after the edit before declaring the structural repair verified.
- Why it helps: A prior live cron record showed `RuntimeError: Context length exceeded (156,832 tokens). Cannot compress further.` The refreshed deterministic audit now measures 156,134 static characters before runtime system/tool overhead, with 99,195 characters coming from the broad operating-system skill package. The latest scheduled run succeeded, so the current posture is recovery with structural risk rather than active failure.
- Risk/safety notes: Scoped internal cron-payload maintenance only. Before writing, require the live prompt+skills SHA-256 to match the reviewed current fingerprint in `/opt/data/agent-bridge/recurring-jobs/context-compaction-preview-latest.json`; if it differs, stop and regenerate the preview. Only `prompt` and `skills` may change. Do not pause, resume, or manually rerun the job. No gateway restart or other gateway operation. No profile, provider, credential, access, schedule, delivery, toolset, or routing change. No Slack send or Telegram change. No production/public/customer-facing action, spending, destructive change, external outreach, private-data expansion, or security-sensitive change. Rollback is restoring only the reviewed prompt and skill list from captured pre-change evidence if the next scheduled run regresses.
- Approval options: approve / reject / revise.
- D.E.V. recommendation: approve the compact-payload repair; it directly addresses the observed failure while preserving the canonical file-based operating rules and the existing job cadence/delivery.
- Live evidence update (2026-07-26T13:12:26Z): `hermes --profile dev cron list --all` shows the latest scheduled run at `2026-07-26T10:07:14.960021+00:00` succeeded. The refreshed audit measures 156,134 static characters and labels the job `RECOVERED / STRUCTURAL RISK`; the compaction preview projects 50,251 characters (`PASS`) and now includes a compare-and-swap stale-preview guard. Keep the scoped repair decision open, but do not portray the prior overflow as the current last-run state.

2026-07-08 — Central Command delivery path triage for live loop failures

- ⚠️ APPROVAL NEEDED
- Title: Approve scoped remediation for D.E.V. proactive loop Slack/send and provider 429 failures
- Proposed action: Approve a scoped maintenance pass in response to `health-precheck` warnings, limited to:
  1. Pausing or keeping paused only the specifically impacted recurring jobs that continue to fail delivery/429 until root-cause is identified and no longer show repeated failures,
  2. Running `python3 /opt/data/profiles/dev/scripts/central-command-room-smoothness-audit.py`, `/opt/data/profiles/dev/scripts/recurring-job-triage-ledger-refresh.py`, and `/opt/data/profiles/dev/scripts/recurring-job-triage-ledger-health-audit.py` for fresh evidence,
  3. Producing a short J.A.R.V.I.S.-reviewed resume/fix decision only after evidence confirms no provider 429 spike and no gateway transport instability.
- Why it helps: The latest proactive precheck shows repeated command-center loop failures (`Slack send failed: cannot schedule new futures after interpreter shutdown`) and provider 429s; pausing/remediation without approvals could mask a deeper process transport issue.
- Risk/safety notes: Scope is internal. Explicitly blocked without separate approval: Slack routing edits, gateway restarts, profile/provider credential adjustments, Slack/Telegram routing config, job resume or unpause, production/public/customer-facing action, spending, destructive change, external outreach, private-data movement, and security-sensitive config changes.
- Approval options: approve / reject / revise.
- D.E.V. recommendation: approve a scoped maintenance-only pass with fresh evidence review, no routing/profile/gateway changes, and no resume/unpause actions until stability is independently confirmed.
- Relevance status (2026-07-26): SUPERSEDED-REVIEW — the listed read-only audits have already been refreshed, job `a2b36554c067` remains paused/triaged with a 40-day-old delivery warning, and mission action `2026-06-30-ACTION-002` is `DONE WITH EVIDENCE`. The remaining live validation decision is already represented by the separate `Human-triggered Central Command live drill` item. Keep this item pending for Stufio review, but do not ask it first unless it is rewritten against current evidence.

2026-07-03 — Nimbus active-agent status confirmation

- ⚠️ APPROVAL NEEDED
- Title: Confirm whether Nimbus should be promoted into the ACTIVE agent roster
- Proposed action: Confirm one of three options for Nimbus: (1) promote Nimbus to ACTIVE and authorize D.E.V./J.A.R.V.I.S. to create/update the activation acceptance packet, active roster row, and standing-duties resume matrix row; (2) keep Nimbus as a non-active mascot/IP/world concept while preserving the existing Nimbus profiles/protocols as draft or specialized support surfaces; or (3) revise Nimbus into a different operating tier such as `ACTIVE (creative/canon only)` with explicit routing limits.
- Why it helps: D.E.V.'s identity drift audit found `/opt/data/profiles/nimbus/`, `/opt/data/profiles/nimbus-ultimate/`, and `/opt/data/agent-bridge/nimbus/` operational protocol evidence while `/opt/data/agent-bridge/ACTIVE_AGENT_ROSTER.md` still says Nimbus is not operational by default. Resolving this prevents J.A.R.V.I.S. from accidentally routing work to an unconfirmed agent or ignoring a now-operational one.
- Risk/safety notes: Low risk if limited to confirmation and internal documentation updates. Safety boundary: no gateway restart, no Slack/Telegram routing change, no credential/access change, no profile/SOUL edit, no job resume, no public/customer-facing authority, no spending, no destructive action, no external outreach, and no security-sensitive change unless separately scoped and approved.
- Approval options: approve option 1 / approve option 2 / approve option 3 with wording / reject / revise.
- D.E.V. recommendation: approve option 3 if Nimbus is intended to operate with Stufio/J.A.R.V.I.S.; use a limited `ACTIVE (creative/canon only)` tier until readiness, tool boundaries, and resume duties are fully packeted.

2026-07-03 — D.E.V. task intake stale-marker cleanup convention

- ⚠️ APPROVAL NEEDED
- Title: Reversible cleanup convention for stale D.E.V. task intake markers
- Proposed action: Approve a reversible cleanup convention for `/opt/data/agent-bridge/dev-tasks/` where J.A.R.V.I.S. or D.E.V. may create `done-<task-id>.json` evidence summaries for stale `inprog-*` markers and move the old `inprog-*` files into a dated archive folder only when `/opt/data/profiles/dev/scripts/dev-task-intake-reconciliation-audit.py` shows completion evidence and no unresolved live execution is needed.
- Why it helps: The task watcher can keep running without stale completed work looking active forever. Current audit evidence shows 4 stale in-progress markers with completion evidence, but they remain `APPROVAL-SENSITIVE — HOLD` until a cleanup/closure convention is approved.
- Risk/safety notes: Low risk if limited to reversible archival and evidence summaries. Safety boundary: no gateway restarts; no credential, provider, access, cron job, routing, Slack/Telegram delivery, production/public/customer-facing, spending, destructive, external outreach, private-data scope, or security-sensitive changes; do not delete task files; do not re-dispatch stale tasks as part of this cleanup convention.
- Approval options: approve / reject / revise.
- D.E.V. recommendation: approve the reversible archive-plus-done-summary convention, with a before/after evidence note for each cleanup pass.

2026-07-01 — Central Command live room drill authorization

- ⚠️ APPROVAL NEEDED
- Title: Human-triggered Central Command live drill
- Proposed action: Approve a human-triggered Central Command live drill using `/opt/data/agent-bridge/CENTRAL_COMMAND_LIVE_DRILL_PROMPT_PACK.md` and `/opt/data/agent-bridge/CENTRAL_COMMAND_DRILL_RESULT_CAPTURE_TEMPLATE.md`, with no gateway restart, no profile/config edit, no credential/access change, no Telegram re-enable, and no job resume unless separately approved after the drill evidence is captured.
- Why it helps: Verifies the shared Slack command room behavior with real evidence before any routing, gateway, or high-frequency build-loop change. The prompt pack now provides exact Slack prompts, pass/fail criteria, stop conditions, and evidence paths for floor control, no duplicate/echo replies, J.A.R.V.I.S. chairing, and safe Central Command smoothness. The new drill evidence index at `/opt/data/agent-bridge/central-command/drill-evidence-index-latest.md` confirms whether captured evidence is actual live-result evidence or only supporting runbooks/tests before any room change is considered.
- Risk/safety notes: Low risk if limited to a human-triggered Slack drill and evidence capture. Higher-risk actions remain blocked: gateway restart, Slack routing edits, specialist profile edits, Telegram re-enable, credential/access changes, provider changes, and resuming paused LLM loops.
- Approval options: approve / reject / revise.
- D.E.V. recommendation: approve the drill-only scope when Stufio wants live room validation; do not resume job `a2b36554c067` or change routing until drill evidence is captured and reviewed.

2026-07-04 — Central Command N.E.X.U.S. free-response drift repair

- ⚠️ APPROVAL NEEDED
- Title: Repair N.E.X.U.S. Central Command free-response drift
- Proposed action: Approve D.E.V. to perform a scoped repair-only Central Command normalization pass for `/opt/data/profiles/nexus/config.yaml`: remove `C0B9FNP86P7` from `slack.free_response_channels` while preserving N.E.X.U.S. Central Command access, channel prompt, name triggers, ignore triggers, and no-bot-loop posture; then run the gateway restart safety audit and restart only the affected N.E.X.U.S. gateway if the config change requires it.
- Why it helps: The new room smoothness audit at `/opt/data/agent-bridge/central-command/room-smoothness-audit-latest.md` found N.E.X.U.S. still has Central Command in specialist free-response channels even though this was previously recorded as normalized. Repairing the drift reduces duplicate/noisy room replies and supports J.A.R.V.I.S. chair/floor-control behavior.
- Risk/safety notes: Low-to-medium operational risk because it touches an active specialist profile and may require a targeted gateway restart.
- Safety boundary: repair-only scope; no gateway restart except the affected N.E.X.U.S. gateway after the restart safety audit if needed; no credential/access/provider change, no Slack token exposure, no Telegram re-enable, no job resume, no public/customer-facing action, no production/DNS/hosting change, no spending, no destructive action, no external outreach, no private-data expansion, and no security-sensitive setting beyond the exact free-response normalization.
- Approval options: approve / reject / revise / defer until after live room drill.
- D.E.V. recommendation: approve repair-only if Central Command smoothness is a priority now; otherwise defer until after the human-triggered live drill, but keep room smoothness claims on HOLD while the drift remains.
- Relevance status (2026-07-27): SUPERSEDED-REVIEW — the current room smoothness audit shows N.E.X.U.S. with `free_response_ccc=False`, `allowed_ccc=True`, prompt/name/ignore triggers present, and no N.E.X.U.S. finding. The live room remains WATCH for different profile findings (J.A.R.V.I.S., A.C.E., and Iris), which are captured in `/opt/data/agent-bridge/central-command/profile-normalization-decision-packet-latest.md`. Keep this historic item pending for Stufio review, but do not ask it first or use it to authorize a N.E.X.U.S. config/gateway change unless fresh evidence reopens the exact drift.