Human in the loop

Approve every AI agent action before it happens

Your agent does the slow part: reading the ticket, finding the payment, drafting the change. Then it stops and asks. Nothing moves until you say yes.

The short answer

The safest way to let an AI agent act is to separate proposing from doing. In MoltenRock Connect, an agent files a proposal (for example a Stripe refund) with what it read and why. It appears in the Human Queue on your Mac; you approve it with Touch ID or decline it, and only then does Connect send it. The agent never holds a key that could make the change itself.

The problem

Most agent frameworks ask the model to be careful

  • “Please confirm” is not a control
    If the same agent that decides also holds the key, a confident mistake or an injected instruction goes straight through.
  • Some actions can’t be undone
    A refund, a sent invoice or a cancelled subscription is final. The check has to come before, not after.
  • Approvals without context
    A yes/no prompt with no reason and no source data trains people to click yes.

How MoltenRock handles it

Propose, review, approve, send

  • A real proposal
    Each card shows the exact change, why the agent wants it and what it read to get there.
  • Touch ID to approve
    Approving is a deliberate act on your Mac. Declining is one click. Unanswered proposals expire.
  • No write key for the agent
    Connect holds the key and sends the change only after your approval. The agent can’t go around the gate.
  • Customer details stay tokens
    Names and addresses reach the agent as tokens, not as the real values.

How it works

How an approval works

  1. 01
    The agent reads
    Orders, payments, tickets: read actions across your connected platforms.
  2. 02
    It proposes
    On Stripe it can propose refunds, dispute evidence, invoices, credit notes, coupons and more.
  3. 03
    You decide
    The proposal waits in the Human Queue in MoltenRock Connect. Approve with Touch ID, or decline.
  4. 04
    Connect sends it
    Only an approved proposal is sent to Stripe, and the result is recorded.

Straight answer

Where the Human Queue is today

Stays on your Mac

  • The Stripe key, inside MoltenRock Connect
  • Every proposal, decision and result
  • Customer names and addresses, as tokens the agent sees

Leaves your Mac

  • The approved change, sent from your Mac to Stripe
  • What your agent sends to its own AI model
  • Stripe is first; Cloudflare is next, and other platforms stay read-only for now

Questions

What people ask first

Which actions can be approved today?

Stripe: 34 kinds of proposal, including refunds, dispute evidence, fraud reviews, customers, subscriptions, invoices, credit notes, payment links, captures, coupons and promotion codes.

What do I need?

MoltenRock Connect is a free download. Approving proposals needs MoltenRock Pro, from $9.99 a month.

Doesn’t Stripe have its own approvals?

Stripe offers controls for agent keys. The Human Queue adds a local, per-proposal gate with the agent’s reasoning in front of you, and the key never reaches the agent.

Which agents can propose?

Agents connected to MoltenRock Connect over MCP, such as Claude Code, Claude Desktop and Cursor.

Let the agent do the work. Keep the yes.

MoltenRock Connect is free. Approvals come with MoltenRock Pro.