Approvals and governance
Renly's rule is simple: agents propose, people approve. Everything else in the governance stack exists to make that rule fast, auditable, and impossible to bypass quietly.
Approval cards
When an agent wants to change something outside the chat, creating work items, sending to a connector, editing files in a code session, running a command, the action arrives as an approval card:
- See exactly what will change, field by field or diff by diff, before anything runs.
- Approve everything, approve a selection, edit the request first, or reject with feedback the agent learns from.
- Destructive changes require an extra explicit confirmation, and the card cannot be approved by a stray click or keystroke in its first moments on screen.
- Grant always allow for a specific command or folder when you trust a repeated action, scoped to that chat.
The Evidence Passport
Every response carries a defensible record: the model and provider that served it, the policy verdicts that applied, identity, and the actions taken. Export a passport bundle when work needs to stand up to review, audit, or a client question long after the chat ends.
Fail-closed policy enforcement
An independent policy service evaluates agent actions as they happen. When policy says no, the action does not run. When the service cannot decide, Renly errs on the side of asking a human instead of proceeding. Organisation admins control connector availability, device capabilities, and per-agent tool allowlists.
Privacy in the work log
Tool output shown in the work log masks values that look like credentials, API keys, tokens, and connection strings, so a screen share or screenshot does not leak them. Reveal them explicitly when you need to.
Audit trail
Organisation-level audit logs record sign-ins, configuration changes, approvals, and agent actions on eligible plans. Records created by agents are soft-archived rather than hard-deleted, so mistakes are recoverable.