When a person is required, show the whole change, not a vague “Approve?”
Approver shows the old and new destination, who is asking, and what will happen on a separate enrolled device.
Capture fresh exact-action human authority when the customer's mandate or policy requires it.
Identity starts the ceremony. It does not authorize the action.
Authentication establishes control of an enrolled credential. The Approver ceremony adds the exact action, the relying party’s challenge and profile, a fresh decision, and evidence that Gate can verify before execution.
How it works
Four steps across the app and the enforcement boundary.
The approval does not disappear after the tap
The reference apps keep the exact decision and the downstream consequence connected without pretending that authorization proves execution.
Signoff methods
Open reference clients and SDKs capture the decision. The relying party still chooses the acceptable apps, keys, integrity services, and assurance floor.
The ceremony establishes that a pinned enrolled key completed a verified response over exact bytes. It does not prove perception, comprehension, legal sufficiency, or that a compromised device displayed honest pixels.
When signoff is required
Policy defines when accountable signoff is required. These are the most common trigger surfaces.
Why it matters
Different environments need accountable signoff for different reasons. The mechanism is the same; each organization decides what control or legal conclusion the evidence supports.