Human approval queues for costly, risky, or irreversible agent actions.
Version: 1.0.0 | License: MIT | Status: production-oriented v1 foundation
Agents need autonomy, but high-impact actions still require explainable intent, bounded authority, and auditable approval.
An approval packet validator that checks action intent, risk class, budget, rollback plan, approver identity, and execution window.
Agent Escrow Protocol ships as a small, dependency-free CLI and library. It validates a domain-specific JSON packet, emits actionable findings, and gives contributors a concrete surface for adding adapters, richer checks, schemas, and integrations.
Agent app developers, enterprise automation teams, governance engineers.
npm test
npm start -- sampleAnalyze your own packet:
agent-escrow-protocol ./packet.jsonOr pipe JSON:
cat packet.json | node src/cli.js{
"action": {
"kind": "deploy",
"system": "production-api",
"reversible": true
},
"risk": {
"class": "high",
"budgetUsd": 0
},
"approval": {
"approver": "ops@example.org",
"window": "2026-05-01T20:00Z"
}
}const { analyze } = require("./src/index.js");
const report = analyze({
"action": {
"kind": "deploy",
"system": "production-api",
"reversible": true
},
"risk": {
"class": "high",
"budgetUsd": 0
},
"approval": {
"approver": "ops@example.org",
"window": "2026-05-01T20:00Z"
}
});
console.log(report.summary);- Validates required fields for the domain packet.
- Scores readiness from 0 to 100.
- Reports missing or weak governance evidence.
- Suggests next actions and contributor extension points.
- Runs fully offline with no API keys and no network access.
Good first contributions:
- Add Slack approvals.
- Add signed approval receipts.
- Add rollback runners.
- Add policy packs.
Larger contributions:
- Add a JSON Schema and compatibility tests.
- Build import/export adapters for popular AI frameworks.
- Add real-world fixtures from public, non-sensitive examples.
- Improve scoring with transparent, documented heuristics.
- Human agency over blind automation.
- Open standards over vendor lock-in.
- Auditable decisions over hidden magic.
- Privacy and safety as design constraints, not release notes.
The marketing site lives in site/index.html. Enable GitHub Pages from the site folder or use the included Pages workflow after publishing.
This project does not process secrets by default. If you build adapters that touch production systems, keep least privilege, explicit consent, and auditable logs in the design.