Approve every AI agent action before it happens
Your agent does the slow part: reading the ticket, finding the payment, drafting the change. Then it stops and asks. Nothing moves until you say yes.
The short answer
The safest way to let an AI agent act is to separate proposing from doing. In MoltenRock Connect, an agent files a proposal (for example a Stripe refund) with what it read and why. It appears in the Human Queue on your Mac; you approve it with Touch ID or decline it, and only then does Connect send it. The agent never holds a key that could make the change itself.
The problem
Most agent frameworks ask the model to be careful
- “Please confirm” is not a controlIf the same agent that decides also holds the key, a confident mistake or an injected instruction goes straight through.
- Some actions can’t be undoneA refund, a sent invoice or a cancelled subscription is final. The check has to come before, not after.
- Approvals without contextA yes/no prompt with no reason and no source data trains people to click yes.
How MoltenRock handles it
Propose, review, approve, send
- A real proposalEach card shows the exact change, why the agent wants it and what it read to get there.
- Touch ID to approveApproving is a deliberate act on your Mac. Declining is one click. Unanswered proposals expire.
- No write key for the agentConnect holds the key and sends the change only after your approval. The agent can’t go around the gate.
- Customer details stay tokensNames and addresses reach the agent as tokens, not as the real values.
How it works
How an approval works
- 01The agent readsOrders, payments, tickets: read actions across your connected platforms.
- 02It proposesOn Stripe it can propose refunds, dispute evidence, invoices, credit notes, coupons and more.
- 03You decideThe proposal waits in the Human Queue in MoltenRock Connect. Approve with Touch ID, or decline.
- 04Connect sends itOnly an approved proposal is sent to Stripe, and the result is recorded.
Straight answer
Where the Human Queue is today
Stays on your Mac
- The Stripe key, inside MoltenRock Connect
- Every proposal, decision and result
- Customer names and addresses, as tokens the agent sees
Leaves your Mac
- The approved change, sent from your Mac to Stripe
- What your agent sends to its own AI model
- Stripe is first; Cloudflare is next, and other platforms stay read-only for now
Questions
What people ask first
Which actions can be approved today?
Stripe: 34 kinds of proposal, including refunds, dispute evidence, fraud reviews, customers, subscriptions, invoices, credit notes, payment links, captures, coupons and promotion codes.
What do I need?
MoltenRock Connect is a free download. Approving proposals needs MoltenRock Pro, from $9.99 a month.
Doesn’t Stripe have its own approvals?
Stripe offers controls for agent keys. The Human Queue adds a local, per-proposal gate with the agent’s reasoning in front of you, and the key never reaches the agent.
Which agents can propose?
Agents connected to MoltenRock Connect over MCP, such as Claude Code, Claude Desktop and Cursor.
Let the agent do the work. Keep the yes.
MoltenRock Connect is free. Approvals come with MoltenRock Pro.