Proposed, not done
An approval controls what's about to happen.
It never pretends to undo work that already completed — it stops the consequential step before it happens, not after.
An office runs on sign-off: someone with authority reviews the consequential step before it goes out. Chatticus applies the same boundary to every bot in the organization — sending, publishing, buying, deleting, and changing permissions all pause at an approval a person controls.
Proposed, not done
It never pretends to undo work that already completed — it stops the consequential step before it happens, not after.
Narrow rules, human default
Auto-review rules can require approval, always allow, or never allow a specific action — but if a require-approval rule and an always-allow rule both match, approval wins. Broad rules like "allow everything in the browser" aren't accepted.
Locked steps stay locked
For passwords, two-factor codes, CAPTCHAs, and payments, the computer hands back to a person for that one step, then returns control — nothing sensitive is pasted into a transcript.
A consequential action reached with no one watching the screen stops on its own or waits on a pre-authorized rule — it never proceeds silently.
Policy checks run at every consequential system sink — the point where an action would actually take effect, not just where it was requested.
Approval cards and human takeover live in the product app, so a hold is resolved where you are already working instead of on the computer's own screen.