Scenario
An agent can execute production SQL changes. We require meaningful human verification with escalation on timeout.Example App
Reference implementation:examples/openai-agents-change-control/
- uses
attesta_approval_handler - sets
fail_mode: escalate - records audit evidence for each tool call
Core Pattern
Production Notes
- route escalated outcomes into a ticketed out-of-band workflow
- require
change_ticketmetadata for every destructive action - alert on repeated timeout escalations to detect approval-path drift