The agent is about to commit a refund, send an email, or push a change. You want the workflow speed of an agent and the certainty that a human said yes before the irreversible part.
Refunds, account changes, infra changes, money movement, customer-visible communication, deletes.
Internal read-only operations, search, summarisation, draft generation. Approval gates kill UX when the action is reversible.
Describe this pattern to the builder assistant and it wires it up for you, brains, tools and triggers. It's vibe coding for agents, no config to write.
Walking through the pattern one piece at a time so the design is clear, not memorised.
The system prompt teaches the agent to ask first. The hook enforces it: even if the agent forgets, the runtime gates destructive calls before they reach the network.
context_builder.ask_user pauses the agent, surfaces the question to the user, and resumes when they answer. The choice becomes a normal tool result the agent reads.
The gate action on tool_start blocks the specific irreversible call outright, with a reason the model (and the user, in logs) can read.
tools.capabilities.grant explicitly names context_builder's ask_user tool - nothing is implicitly available, every capability is a deliberate line in the YAML.
The pattern above is not the only answer. Here is when something else is the right call.
Have the agent emit a plan first, the user approves the plan, then the agent executes the whole plan without per-step prompts. Less interruption, larger blast radius if approval is given to an underspecified plan.
Agent does the work, posts a draft for human review elsewhere (a message, a ticket). Humans approve later. Higher throughput, weaker safety because the action is already taken.
Engineering notes from the Digitorn team. No marketing, no launch announcements, no "10 prompts that will change your life". Just the things we write that we'd want to read.