Skip to content
AI Interfaces block

Approval Policy List

Which agent actions run unattended and which need a signature, stated as a policy the operator can read before anything happens.

156 linesNo dependenciesAdded 9 Sept 2026Updated 10 Sept 2026
  • approval
  • policy
  • guardrails
  • permissions
  • agent

What's included

  • components/approval-policy-list.tsx
  • No runtime dependencies

Works with

  • React
  • Next.js
  • Tailwind CSS
  • TypeScript

npx hoverlab add approval-policy-list

Or over MCP, from your editor's agent — no account needed.

License

Free to read, copy and install, for personal and non-commercial projects. Shipping it in client work or a paid product needs Pro ($79 once). The source lands in your repo and stops being ours — no attribution, nothing to upgrade.

Was this useful?

Start a page with this section — add more, order them, and leave with the page source.

Preview

What runs without asking

Approval prompts are trusted in proportion to how predictable they are. Someone who cannot say in advance which actions will stop and ask learns to approve everything.

Rendered live in your current theme — this is the same component whose source is below, not a screenshot of it.

Source

components/approval-policy-list.tsx
'use client'

/**
 * <ApprovalPolicyList> — Which agent actions run unattended and which need a signature, stated as a policy the operator can read before anything happens.
 *
 * Approval prompts are trusted in proportion to how predictable they are.
 * Someone who cannot say in advance which actions will stop and ask learns
 * to approve everything, at which point the prompts are theatre. The layout
 * problem is therefore not the prompt at all — it is stating the policy
 * before anything runs.
 *
 * The obvious wrong answer is a two-column allowed/blocked table. Real
 * policies have three states, and the third is the interesting one: actions
 * that run unattended, actions that ask, and actions that are refused
 * outright with no approval available. A binary table has to file "delete
 * production data" under the same heading as "send an external message",
 * and they are not the same promise.
 *
 * So the list runs from unattended to blocked, and the badge names which of
 * the three it is. Ordering it that way means the reader's eye stops at the
 * point the policy tightens, which is the boundary they came to find.
 *
 * The money row's detail carries the part most policies leave out — the
 * approval expires rather than waiting indefinitely. An approval that sits
 * open for a day is a signature on something the signer no longer
 * remembers.
 *
 * Rows are buttons with `aria-pressed`: a real implementation opens the rule
 * behind a row, so it is operable. `status` is separate from `tone` so
 * "asks" and "blocked" are readable without colour, which matters more here
 * than anywhere else in this catalog — a policy whose severity is carried
 * only by a red pill is a policy some readers cannot read.
 *
 * The demo selects the first row, the least restrictive one, so the panel
 * opens on the state most actions are in.
 */

import * as React from 'react'

type Tone = 'neutral' | 'positive' | 'warning' | 'critical'

export interface ApprovalPolicyListRow {
  id: string
  label: string
  detail?: string
  tone?: Tone
  /** What the badge says. Falls back to the tone name when absent. */
  status?: string
}

export interface ApprovalPolicyListProps {
  heading?: string
  intro?: string
  rows?: ApprovalPolicyListRow[]
  className?: string
}

/*
  Tones as complete utility classes, never assembled from fragments.
  Tailwind scans source text, so `text-${tone}-foreground` produces no
  class at all — the same failure as an undefined token, and just as
  invisible in review.
*/
const TONE_CLASS: Record<Tone, string> = {
  neutral: 'bg-muted text-muted-foreground',
  positive: 'bg-primary/10 text-primary',
  warning: 'bg-accent text-accent-foreground',
  critical: 'bg-destructive/10 text-destructive',
}

const ROWS: ApprovalPolicyListRow[] = [
  { id: "row-1", label: "Read anything", detail: "Runs unattended. Every read is logged with the query that caused it.", tone: "positive", status: "unattended" },
  { id: "row-2", label: "Draft and edit documents", detail: "Runs unattended in a draft state. Publishing is a separate action.", tone: "positive", status: "unattended" },
  { id: "row-3", label: "Send an external message", detail: "Always asks. The recipient and the full body are shown before you sign.", tone: "warning", status: "asks" },
  { id: "row-4", label: "Spend money or change a plan", detail: "Always asks, and the approval expires after five minutes rather than waiting.", tone: "critical", status: "asks" },
  { id: "row-5", label: "Delete production data", detail: "Blocked outright. There is no approval that turns this on from here.", tone: "critical", status: "blocked" },
]

export function ApprovalPolicyList({
  heading = "What runs without asking",
  intro = "Approval prompts are trusted in proportion to how predictable they are. Someone who cannot say in advance which actions will stop and ask learns to approve everything.",
  rows = ROWS,
  className,
}: ApprovalPolicyListProps) {
  /*
    Per-instance prefix for every id this block emits.

    The literals these replaced were a latent duplicate the moment the
    block appeared twice on one document, and `aria-labelledby` on a
    duplicated id resolves to the first match -- so the second copy was
    labelled by the first copy's heading. Client component, so `useId` is
    the right tool.
  */
  const uid = React.useId()

  const [selected, setSelected] = React.useState<string | null>(rows[0]?.id ?? null)

  return (
    <section
      aria-labelledby={`${uid}-approval-policy-list-heading`}
      className={`w-full bg-background px-6 py-16 ${className ?? ''}`}
    >
      <div className="mx-auto max-w-3xl">
        <h2
          id={`${uid}-approval-policy-list-heading`}
          className="text-2xl font-semibold tracking-tight text-foreground"
        >
          {heading}
        </h2>
        <p className="mt-2 text-sm text-muted-foreground">{intro}</p>

        <ul className="mt-8 divide-y divide-border overflow-hidden rounded-xl border border-border bg-card">
          {rows.map((row) => {
            const isSelected = row.id === selected
            return (
              <li key={row.id}>
                {/*
                  A button, not a div with onClick. The row is operable, so
                  it has to be reachable by keyboard and announce its
                  selected state — aria-pressed is what carries that.
                */}
                <button
                  type="button"
                  aria-pressed={isSelected}
                  onClick={() => setSelected(row.id)}
                  className={`flex w-full items-center justify-between gap-4 px-5 py-4 text-start transition-colors hover:bg-muted/60 focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-ring focus-visible:ring-inset ${
                    isSelected ? 'bg-muted/40' : ''
                  }`}
                >
                  <span className="min-w-0">
                    <span className="block truncate text-sm font-medium text-foreground">
                      {row.label}
                    </span>
                    {row.detail ? (
                      <span className="mt-0.5 block text-sm text-muted-foreground">
                        {row.detail}
                      </span>
                    ) : null}
                  </span>
                  <span
                    className={`shrink-0 rounded-full px-2.5 py-1 text-xs font-medium ${
                      TONE_CLASS[row.tone ?? 'neutral']
                    }`}
                  >
                    {row.status ?? row.tone ?? 'neutral'}
                  </span>
                </button>
              </li>
            )
          })}
        </ul>
      </div>
    </section>
  )
}

Before you paste

  • Styling is Tailwind utility classes on semantic tokens (bg-card, text-muted-foreground) — it inherits your theme instead of overriding it.
  • Nothing to install. No component library, no icon package.
  • Every prop has a default, so it renders standalone before you wire it up.

Where it goes

Drop it at components/approval-policy-list.tsx and import it where you need the section:

import { ApprovalPolicyList } from '@/components/approval-policy-list'

Customize

1 of this block’s props are simple enough to drive from here. Change them and the block below re-renders — it is the same component whose source is above, not a mock of it. Everything else it accepts is in the table underneath.

Props

Read out of the component’s own type and signature, so this cannot drift from the source below. Every prop has a default — the component renders standalone before you pass it anything.

PropTypeDefault
headingstring"What runs without asking"
introstring—
rowsApprovalPolicyListRow[]ROWS
classNamestring—

Not using React?

The same block rendered once to markup, wrapped as a file your framework compiles. Tailwind classes are framework-agnostic, so the design transfers intact — the behaviour does not.

This block is interactive. The markup below is its initial state with the event handlers stripped — you will need to re-wire the behaviour in your framework.

approval-policy-list.html
<!--
  Approval Policy List — markup from the Hoverlab catalog.

  This is the block rendered once to HTML and wrapped as a component
  file. It is not a port of the React source: the Tailwind classes carry
  the design, which is the part that took the work, and they are the same
  in every framework.

  This block is interactive in React and the handlers are NOT here.
  Buttons, toggles and menus render in their initial state and do
  nothing until you wire them up.
-->
<section aria-labelledby="_R_0_-approval-policy-list-heading" class="w-full bg-background px-6 py-16 ">
  <div class="mx-auto max-w-3xl">
    <h2 id="_R_0_-approval-policy-list-heading" class="text-2xl font-semibold tracking-tight text-foreground">What runs without asking</h2>
    <p class="mt-2 text-sm text-muted-foreground">Approval prompts are trusted in proportion to how predictable they are. Someone who cannot say in advance which actions will stop and ask learns to approve everything.</p>
    <ul class="mt-8 divide-y divide-border overflow-hidden rounded-xl border border-border bg-card">
      <li>
        <button type="button" aria-pressed="true" class="flex w-full items-center justify-between gap-4 px-5 py-4 text-start transition-colors hover:bg-muted/60 focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-ring focus-visible:ring-inset bg-muted/40">
          <span class="min-w-0">
            <span class="block truncate text-sm font-medium text-foreground">Read anything</span>
            <span class="mt-0.5 block text-sm text-muted-foreground">Runs unattended. Every read is logged with the query that caused it.</span>
          </span>
          <span class="shrink-0 rounded-full px-2.5 py-1 text-xs font-medium bg-primary/10 text-primary">unattended</span>
        </button>
      </li>
      <li>
        <button type="button" aria-pressed="false" class="flex w-full items-center justify-between gap-4 px-5 py-4 text-start transition-colors hover:bg-muted/60 focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-ring focus-visible:ring-inset ">
          <span class="min-w-0">
            <span class="block truncate text-sm font-medium text-foreground">Draft and edit documents</span>
            <span class="mt-0.5 block text-sm text-muted-foreground">Runs unattended in a draft state. Publishing is a separate action.</span>
          </span>
          <span class="shrink-0 rounded-full px-2.5 py-1 text-xs font-medium bg-primary/10 text-primary">unattended</span>
        </button>
      </li>
      <li>
        <button type="button" aria-pressed="false" class="flex w-full items-center justify-between gap-4 px-5 py-4 text-start transition-colors hover:bg-muted/60 focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-ring focus-visible:ring-inset ">
          <span class="min-w-0">
            <span class="block truncate text-sm font-medium text-foreground">Send an external message</span>
            <span class="mt-0.5 block text-sm text-muted-foreground">Always asks. The recipient and the full body are shown before you sign.</span>
          </span>
          <span class="shrink-0 rounded-full px-2.5 py-1 text-xs font-medium bg-accent text-accent-foreground">asks</span>
        </button>
      </li>
      <li>
        <button type="button" aria-pressed="false" class="flex w-full items-center justify-between gap-4 px-5 py-4 text-start transition-colors hover:bg-muted/60 focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-ring focus-visible:ring-inset ">
          <span class="min-w-0">
            <span class="block truncate text-sm font-medium text-foreground">Spend money or change a plan</span>
            <span class="mt-0.5 block text-sm text-muted-foreground">Always asks, and the approval expires after five minutes rather than waiting.</span>
          </span>
          <span class="shrink-0 rounded-full px-2.5 py-1 text-xs font-medium bg-destructive/10 text-destructive">asks</span>
        </button>
      </li>
      <li>
        <button type="button" aria-pressed="false" class="flex w-full items-center justify-between gap-4 px-5 py-4 text-start transition-colors hover:bg-muted/60 focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-ring focus-visible:ring-inset ">
          <span class="min-w-0">
            <span class="block truncate text-sm font-medium text-foreground">Delete production data</span>
            <span class="mt-0.5 block text-sm text-muted-foreground">Blocked outright. There is no approval that turns this on from here.</span>
          </span>
          <span class="shrink-0 rounded-full px-2.5 py-1 text-xs font-medium bg-destructive/10 text-destructive">blocked</span>
        </button>
      </li>
    </ul>
  </div>
</section>
  • This is rendered HTML, not a translation of the React source. The Tailwind classes carry the design and work in any framework.
  • It is one frame: the component in its initial state, with no props applied beyond the defaults.
  • This block is interactive in React — toggles, menus or form state. None of that survives here; the markup is the closed/default state and the handlers are gone. Re-wire them in your own framework.
  • Requires Tailwind, and the design tokens the classes reference (bg-card, text-muted-foreground, and so on). The template ZIPs ship a globals.css that defines them.

What each framework gets across the whole catalog — effects convert properly; this rung is markup.

For AI

The component, its props, the design tokens it expects and the command that installs it — as one prompt. Paste it into Claude, Cursor, v0 or ChatGPT and what they build around it will match the rest of the catalog instead of inventing its own system.

See the prompt

Used in these pages

Want the whole screen instead of this one section? Open a page and copy it entire.

7 more blocks in Human in the Loop

All of them free to read, copy and install — no account, no locked tiles, no watermarked preview. The whole catalog is open, and so are the API and the CLI.

Browse Human in the Loop

Shipping one commercially

Copying the code is free. Putting it in client work or a paid product is what Pro is for — the licence, not the access.

  • A commercial licence for everything in the catalog
  • Unlimited bundle exports, in Vue, Svelte and Tailwind
  • One payment — no subscription, nothing to renew
Pro — $79 once

More Human in the Loop blocks

View category
Open the full page for this block

Approval Request with Blast Radius

The agent stops and asks: the effect stated before the verb, choices as radios in a fieldset so picking is separate from committing, no pre-focused Approve, and the decision left on screen afterwards.

Human in the Loop247 lines1 dep
Open the full page for this block

Proposed Edits Diff Table

Machine-proposed row edits accepted one at a time, with before and after in real del/ins elements, a tri-state select-all that actually sets indeterminate, and a running count of what will be written.

Human in the Loop269 lines1 dep
Open the full page for this block

Recommendation with Confidence Meter

A suggestion scored with a native meter rather than a styled bar, banded in words as well as numbers, and showing what the model rejected — the fastest way a human catches a bad recommendation.

Human in the Loop258 lines1 dep
Open the full page for this block

Agent Permission Scopes

Read and write scopes separated rather than bundled, writes off by default, a required expiry, and switches that are real checkboxes with role="switch" — so the grant is toggleable by keyboard and announced as on or off.

Human in the Loop297 lines1 dep
Open the full page for this block

Bulk Approval Queue

Forty decisions and an honest way to clear them: bulk approve that cannot reach the high-impact rows, a select-all that says how many it takes, and the auto-approve deadline on every line.

Human in the Loop307 lines1 dep
Open the full page for this block

Escalation Queue

What is waiting on a person, ordered by how long it has been waiting rather than when it arrived.

Human in the Loop148 linesNo deps
Open the full page for this block

Human Oversight Split

Where a person sits in an automated run, written as four guarantees rather than as a promise that a human is involved.

Human in the Loop156 linesNo deps