Approval rules you define
The Ability Gateway has its own home. A new Gateway section in the sidebar holds Approvals, Activity and Permissions, with a count of pending approvals on the Approvals link.
Approval rules. Under Permissions you now write approval rules. Each one says which abilities, risk levels and environments it covers, who approves (owners, admins, or named people and agents), where they are asked (the incident channel, a DM to each approver, or both), and whether a requester may approve their own request. Rules run in order and the first match wins. Until you write one, nothing waits.
Slack and the dashboard follow the same rules. Grants and approval rules now govern Slack and the dashboard, not only the API. A Slack action caught by a rule is parked and completes on its own once approved. On the dashboard, a granted ability unlocks the matching controls, and a member without it sees the list without the buttons.
Request source. Activity and Approvals show the source of every request, whether web, Slack, API or MCP.