Port Workflows Human Approval and Permissions Guide

On this page

Quick answer

Port describes workflow permissions and approval resolution from runtime context such as the user, form values, and catalog relationships. Approval nodes can pause a graph until the required reviewer acts.

Define who may trigger separately from who must approve. A person’s ability to view a workflow, receive a notification, or comment does not grant approval or execution authority.

Approval contract

Record the subject, requested action, resource, environment, risk, evidence, requester, eligible reviewers, separation-of-duties rule, expiry, escalation, rejection path, and whether a later retry needs new approval. Resolve dynamic reviewers from authoritative catalog ownership and test missing or stale ownership.

The audit record should make the input, agent output, human decision, identity, time, and resulting downstream action reconstructable. Test self-approval, removed reviewer, conflicting groups, expired approval, changed input after approval, duplicate callback, timeout, rejection, and rollback.

Continue with the agent and MCP governance guide and readiness checklist.

Official sources

Source check: August 23, 2026. Verify current permission composition, reviewer resolution, audit, notification, timeout, and retry behavior.