pending approvals · decisions bind to the exact arguments shown
signed audit chain
verifying…| seq | time | actor | action | decision | result |
|---|
delegations
| id | agent | budget | status | expires |
|---|
usage — derived from the signed audit chain
| tool | calls | executed | denied | cost |
|---|
approval notification channels · parked approvals push here
Slack and email channels carry secrets — configure them via toolgate channels add-slack / add-email so credentials are sealed straight into the vault.
| id | type | name | status |
|---|
slack bindings · slack user -> operator attribution
| slack user | operator | created |
|---|
per-user oauth connections · agents call with the user's account, never a shared secret
Register provider apps via toolgate oauth add-app (the client secret is sealed straight into the vault). Send the authorize URL to the user; the callback completes the connection.
| id | user | app | status | token expires |
|---|
policy simulator · would the gate allow this call?