Skip to main content

The Inbox App

The Inbox is where workflows wait for you. When a workflow reaches a human-in-the-loop gate, the run pauses and the gate appears in the Inbox for a person to decide.

What arrives here

Pending approval gates — the points where a running workflow needs a human decision before it continues (the Custom HIL and Customer Confirm nodes). Use the type selector to switch between Product document update, Risk sign-off, Control findings, Lessons learned, and Cost allocation gates. Each pending item shows the workflow it came from, the gate, how long it's been waiting, and the authority level required to act on it. Resolved items are available on a dedicated history page.

Making a decision

When a workflow reaches a Human-in-the-Loop (HIL) gate, it pauses and routes a decision request to your Inbox.

To prevent "approve-blind" decisions, the Inbox features a live review-context viewer. This viewer displays the full proposed change (such as a rendered document proposal) directly within the gate interface, allowing you to review exactly what you are approving before making a decision. When approving a change that would remove existing section content, a prominent warning banner appears above the decision controls stating the removal.

Your available actions are determined by your authority rung for that workflow: reviewers may Verify, Acknowledge, or Reject; approvers may Approve, Reject, or Escalate; owners may Approve or Reject. For gates requiring multiple attestations, the interface shows live progress (filled of total) and records each decision without resolving until quorum is met. A required reason is recorded with every decision.

A signed, verifiable record

Every decision is written to a tamper-evident, hash-chained record. Resolved gates are available on a dedicated history page reachable from the Inbox header. The page lists decisions newest-first, supports server-side search across all resolved gates in the organization, and lets you filter by gate type (product document updates or risk sign-offs). Selecting a record opens its full signed lineage, chain-verification status, and outcome in a side pane or drawer. Each entry shows the recorded decision, who made it, and when.

Live updates

The Inbox updates in real time — new gates appear and resolved ones clear without a manual refresh.

Ask about the gate you're viewing

The Inbox includes Mira, a grounded companion presented as a docked right-hand panel. With a gate, risk, or control finding selected, Mira scopes its answers to that item (its workflow, the pending decision, the attestation state, or the register) and states that scope in the panel. It answers only from the item's real facts. You can converse in any of over twenty supported languages, use your microphone for voice input, and optionally have Mira's replies spoken aloud. A quiet, rotating daily reflection appears above each session. Suggested questions appear when a record is selected and the conversation has not yet begun.

Risk sign-off

The Inbox surface also includes a dedicated Risk sign-off queue, selectable via the type menu. Here you review engine-suggested risks (with their source, severity, root cause, and aligned drift evidence) before confirming them to authored status or rejecting them with a required reason. Each decision is recorded individually; there is no bulk action. A separate "Product document update" type covers workflow-driven approval gates.

Control findings

The Inbox also carries a Control findings queue, selectable from the type menu. Where the Risk sign-off queue asks whether a risk is real, this one asks whether a program has breached one of your governance controls.

Suggested findings arrive here for a decision. They are grouped by the control they breach, so you review one control's breaches together, and the control's own criteria — the interpretive standard the program is measured against — is shown once above the group. Each finding lists the control's level (levels 4 and 5 gate; levels 1 to 3 are advisory), the program concerned, the finding statement, and whether it was engine-flagged or raised by a person.

You have two actions. Confirm opens the finding as a tracked governance issue. Dismiss closes it and requires a written reason saying why it is not a real breach — the control is disabled until you provide one. Reading the control and the breach before deciding is the point of the surface: a confirmation is a signed governance decision, not a bare yes or no. Each decision is individual; there is no bulk action. Only organization owners and administrators can decide.

When the queue is empty it says so plainly — every suggested finding has been reviewed — rather than showing an empty list.

Decided findings move to the resolved history, newest first, alongside your other resolved gates. Each entry shows the outcome (Confirmed or Dismissed), the program, the control that was breached, who decided and when, and — where one was given — the dismissal reason in their own words.

Lessons learned

The Inbox also carries a Lessons learned queue, selectable from the type menu. When a risk-carrying program completes, a drafted lesson appears here for confirmation. Each item shows the program (epic), how many risks or close-out references ground it, and whether the draft has been edited. The detail pane displays the full grounding (authored risks with severity, signed decisions that produced them, or close-out references including substantiated_by and cannot_substantiate lists), the drafted lesson text (editable before signing), and the confirm/reject controls. An edit is recorded as an amendment. For candidate trust-close items (hand-closed with no machine evidence), a separate attest action lets a named person stand behind the closure; the agent cannot attest. Confirmed lessons leave the queue and appear in resolved history with their frozen evidence.

Cost allocation

The Inbox also carries a Cost allocation queue, selectable from the type menu. A deterministic proposal appears when a program's money-at-risk (total budget × overdue share) suggests a cost-center allocation. The detail pane shows the suggested amount, the current allocation (if any), and the grounding formula so you ratify a reasoned figure rather than a bare number. You may amend the amount within ratification; both the original proposal and your amendment are recorded. Confirm applies the allocation atomically with provenance. Reject requires a written reason. Each decision is individual; there is no bulk action.

A footer on Inbox surfaces shows recent AI compute usage for the organization: the rolling window label, approximate USD cost (to four decimals when under one cent), total tokens, call count, and the top three surfaces by spend. An explicit note appears when any models lack published pricing so the figure is understood as a lower bound. The footer is present on every Inbox route and carries the suite wordmark below the cost line.