Decision Desk
Review authoritative Decision Requests and record approve, reject, or escalation outcomes.
Decision Desk is the human decision workspace at /approvals-inbox. Route access requires approval:list unless a full-access role applies. Decision mutations also enforce approval:decide, required reviewer roles, and maker-checker rules.
What it owns
- Work split into Needs decision, Spot checks, and Completed.
- Request context, triggering policy, requested action, required role, due time, and correlation identifiers.
- Approve, reject, and escalation outcomes supported by the request contract.
- Durable receipts with actor, role, decision, timestamp, approval identifier, and audit event identifier.
Decision Requests are authoritative in their approval store. Attention views and compatibility routes only aggregate or redirect them.
Exception lifecycle
flowchart LR S["Signal received"] --> R["Review required"] R --> D["Decision required"] D --> M["Remediation in progress"] D --> E["Evidence ready"] M --> E E --> C["Closed"]
The same signal cannot create duplicate authoritative Decision Requests on retry. Existing execution, run, trace, policy, and decision identifiers remain attached throughout the lifecycle.
Foreign, stale, and unauthorized direct links fail closed and return an unavailable or unauthorized state.
