Black Hat USA Aug 4-6, Mandalay Bay. Book time with us
Operate

Work the seals queue

How to review and decide on pending actions waiting for a human yes.

Updated 2026-07-14
In short

A Seal is an approval step. Before the AI does anything risky or hard to undo, it stops and asks you. The Seals queue is the list of those requests waiting on you. You approve one, deny it, or let it expire, and every choice is recorded.

A Seal is the propose/dispose gate: the AI proposes, a human disposes. The Seals queue is where those proposals land on you. It is the one place every destructive or irreversible action in Soarcery must pass through, whether a triage raised it, a spell reached it mid-cast, or the Familiar produced it from a plain-English request. Every proposal appears here: there is no side door around it.

Propose and dispose

When the AI investigates, it enriches, correlates, and proposes actions. Safe reads proceed on their own, and anything privileged or irreversible defaults to a human decision at a Seal. The AI cannot quietly grant itself more autonomy; widening what runs without you is an explicit change made by a person. The Familiar is held to the same gate, so a destructive request in chat routes here rather than executing.

Two guardrails sit in front of a proposal. An unscored situation gathers more evidence before it proposes anything, rather than guessing at an action on thin data. And a contested verdict can never propose closing something as benign: split opinion always goes to a person, never to a quiet auto-dismissal.

The Seals queue listing pending action proposals grouped by urgency, each showing its rationale and proposed action awaiting approval.
The Seals queue: every proposed action that needs a human yes, grouped by urgency, in one list.

What a pending seal shows

Each pending seal shows what the AI wants to do, on what evidence, and why, along with the reversible plan. Approve it and the action executes exactly once and lands on the ticket timeline: approving from the chip in a conversation and approving from the queue are the same single decision, so a proposal can never fire twice. Deny it and that is recorded too. A seal can also expire if no one acts, which is recorded as its own outcome. A seal can go stale on its own as well: when newer evidence supersedes the reasoning it rested on, the seal invalidates rather than letting you approve a decision the facts have already overtaken.

Deciding from the chat

You do not have to open the queue to act. When the Familiar stages a Seal it offers the decision inline in the conversation, and it can list the Seals waiting on you and read any one back in full. The choices sit side by side with none pushed forward, so nothing nudges you toward approving. The click is yours: it calls the same decision the queue uses, with your own authority, so a Seal decided in chat leaves the queue exactly as if you had decided it there. The Familiar then reports what actually happened: what the action did, or that it failed or was already decided by someone else, never a success it did not get. TheSeals queue stays the place to work through many at once and to read the full audit trail; the chat is for deciding the one in front of you.

Reading the reasoning

Every conclusion the AI reaches carries its trace: the steps, the tool calls, and the evidence behind it. If the AI keeps proposing something you keep denying, the trace tells you whether to fix the detection feeding it or the knowledge it reads. Either way the decision is replayable later: who, what, why, and on which evidence.

More guides

Everything you can teach your Familiar.