Documentation · The Lagstyr handbook
Deciding a proposal
A proposal is a request for authority: a change somebody or something has asked for, frozen with the exact payload that would be applied. When approval would execute a registered skill, the proposal also pins that skill’s exact executable revision. A later catalogue change cannot silently replace what you reviewed; if the pin no longer matches the active contract, approval refuses instead. The governed change takes effect only after approval. The Proposals page lists the proposals waiting for a decision, annotated with whether you may decide each; it never acts. You open a proposal with Review and decide and the decision happens on the proposal’s own page.
The decision card, top to bottom
The page is a sequence of cards, in the order you should read them.
The proposal. Who raised it, when, what it is about, its risk tier, when it expires, and its route to approval: the required approver, and how many approvals it has against how many it needs. If the proposal carries a cooling-off period, the card shows the instant it elapses and says, in words, whether a decision is yet permitted. A decision before that time is refused.
Consequence. Materiality, reversibility, the likely consequence, the uncertainty, and what approval would do. Each of these is declared by the proposer, and an undeclared one reads not declared. The last line matters most. It is one of three sentences: approval executes the authoritative effect automatically; approval records a decision and execution happens out of band; or no active executable mapping was found and approval may have no effect.
Authority scope. The legal entity, subject, counterparty and amount the kernel derived from the payload. Amounts are shown in money, re-scaled from the payload’s units, so a spend cap of fifty dollars reads as fifty dollars and not as its raw integer.
The approval transaction rechecks authority and conflicts against that exact scope. Where the selected route requires a fresh conflict disclosure, the assessment must cover this proposal’s scope completely and still be within both its own expiry and the route’s freshness window. An incomplete, stale or mismatched assessment is a refusal, including an outdated “nothing to declare”.
What this would change. A field-by-field comparison of the record now against the record as proposed, followed by the frozen payload itself, the proposer’s rationale, any evidence attached at proposal time, and the results of validation, policy, diff and canary checks where a resolver supplied them. If the current record could not be read, the page says so and shows you the frozen payload alone. Read it as a payload, not as a comparison.
Lineage and commitments. What this proposal supersedes or escalates, the measurement contract it carries or the exemption it claims, and the agent run that raised it, if one did.
Decisions already recorded. Who has decided so far, when, and the reason they gave.
Approve, reject, or propose a replacement
Approve records your approval with an optional reason. Before it submits, the console tells you exactly what approving will do, in the same three sentences as the consequence card, together with the declared materiality. One approver contributes one decision; if the route needs two, the proposal stays pending until the second arrives.
Reject closes the proposal against, with an optional reason. Rejected is terminal.
Propose a replacement is for the proposal that is nearly right. The payload you authenticate is frozen and cannot be edited, so the console closes the original and opens a new proposal carrying whatever you leave in the form. Both stay in the record, linked. The original is never rewritten.
There is no fourth verb. In particular, an agent cannot approve a proposal, and neither can a notification, a chat message or an email.
How your decision is authenticated
A decision is authenticated, not merely clicked.
If you signed in through your organisation’s identity provider, there is no password field. The console uses your current session, and if that session is no longer fresh enough to decide, it sends you to sign in again and brings you back to the same proposal. Nothing you typed is lost.
If you hold an emergency session, signed in with the local password, you re-enter that password to decide. The console limits attempts to ten a minute.
Why the buttons are sometimes missing
When the console will not offer you a decision, it says so: No decision is offered here, with the reason it can name. You may not hold the role the route requires; you may hold no approval grant for the route; or you may simply not be authorised for this proposal, which includes the case where the route forbids the proposer from deciding their own proposal and you are the proposer. The rule that the proposer cannot be the approver belongs to the approval route, and the Authority page shows you which routes set it.
A proposal that has already been decided offers no buttons either. Its page says: It is a record now, not a decision.