Your agent writes code.
Now it can get feedback too.
You build with agents. But before launch you want feedback or approval from someone else.
Today this is a manual process of screenshots + email or (worse) meetings — all of which slow down the agentic workflow.
HumanGated gives your agents a way to interact with humans on your behalf in a structured way that’s easier for everyone, and faster all around.
Free for prototypes and prompts · reviewers never sign up · links self-expire · we never see your agent's session
“‘Decline if rude’ is a brand risk — I proposed a rewrite.” One comment, one suggested edit — back as a ready-to-apply diff.
You already do this. It's just done by hand.
Six steps, and your agent is stopped for all of them.
-
1
You stop.
Screenshot it. Crop it. Find the one that shows the bug. Your agent is idle and you are now a courier.
-
2
You do the packing.
Attach the PNG. Type out what changed, what you need, and by when. Again. Send. Hope the attachment survived.
-
3
They squint at a JPEG.
Nothing clicks. So they write a paragraph describing a red circle they'd have drawn in one second.
-
4
You wait, blind.
Did it land? Did they open it? Is Thursday still Thursday? Nudge on Friday and feel rude doing it.
-
5
You do the unpacking.
Out of the mail, into the terminal, cut and paste — then re-explain the context your agent was never given.
-
6
Nothing was written down.
The decision now lives in an inbox, a thread, a screenshot folder, and your memory. Ask in March who signed off.
Six steps become four. You do only one.
You say one line. Mike says one thing. Everything between is machinery.
-
1
You say one line.
check with mike — does the refund rule read right?
In the session you're already in. You don't leave, and you don't assemble anything.
-
2
He marks the real thing.
Draws on the page. Highlights the exact span. Picks an option. On his phone, with no account, no password, no app.
-
3
Your agent pulls it back.
Comments anchored to the element he pointed at, his edits as ready-to-apply diffs, and a yes or no it can branch on.
-
4
It wrote itself down.
Who, when, his words verbatim, a checksum he also holds by email, and what you did with it afterwards.
And three things the old way can't do at all
You can't make it a rule.
Today: either everyone remembers to ask, or you build process around it — and process is slower than not using the agents in the first place.
Here the ask itself declares what it is. Mark it
required and a hook outside the model refuses the edit at
the tool call until Mike rules — scoped to the paths you named, so the
agent keeps working on everything else.
Real apps make it worse.
A self-contained prototype you can at least screenshot. The thing that actually needs judgment is the running app — logged in, real data, three steps into a flow. A PNG of that is useless.
Point the ask at the URL you already have running. They open it in their own browser, against real working data, and mark it up there. We never load, embed, or screenshot your page.
There's no record.
A hodge-podge of email, screenshots and Slack. No way to answer "who approved this, and what did we change because of it" without an afternoon of archaeology.
Filter on any part of it — what was reviewed, which version, who, what you asked for, what expired, and what you did about it. It says what it is not, too: a record of what happened, not a certified audit.
Three kinds of “can you look at this?”
A prototype
Was: a cropped PNG and a paragraph explaining where to look.
They draw a box on the thing itself. You get the note, the element it points at, and a screenshot of what they saw.
A prompt, or any text
Was: a paste into Slack, and a reply saying “paragraph two feels off.”
They highlight the exact span and rewrite it in place. Edits come back as diffs your agent can apply.
Your running app
Was: a screenshot of real data, or a meeting you both had to attend.
Point an ask at a URL you already have deployed. They open it in their own browser and answer in their inbox — against real working data, not a self-contained copy. We never load, embed or screenshot your page.
Your agent can build it. Only a person can answer for it.
Taste, judgment and accountability don't have an API. And increasingly you have to be able to show it: the EU AI Act's Article 14 and NIST's AI Risk Management Framework both call for human oversight you can demonstrate, not just assert.
So every gate here leaves a record — who was asked, what they were shown, what they decided, and how sure we are it was really them.
Park the work until a person says yes
Was: a process document, a checklist nobody reads, and hoping everyone remembers to ask.
Ask for a ruling instead of a comment and your agent waits — through a lunch break, through the weekend. Mike taps Ready or Needs revision, and the work resumes where it stopped. Leave a note for whichever session picks it up; nobody has to remember anything.
Add the skills to your coding agent:
npx skills@latest add Brightwing-Systems-LLC/humangated-skills -g --skill '*'
- One install reaches 70+ agents — Claude Code, Codex, Gemini CLI, Cursor, OpenCode, GitHub Copilot, Goose, Windsurf, Zed, Amp, and the rest
- All 11 verbs at once, for your user — not one project, so they work in every repo you open. The installer still shows you its security assessment and asks before it writes anything
- The skills are open source — 11 Markdown files you can read before you install them, in the public repo
- No passwords, ever — one magic-link click links your account; the people you ask never sign up at all
Other ways to install
claude plugin marketplace add Brightwing-Systems-LLC/humangated-skillsclaude plugin install humangated@humangatedPrefer manual? Point your agent at https://humangated.ai/agent.md — it asks before every consequential step.
One ask, start to finish.
A signup screen your agent built, one person’s ruling, and a deadline that means something because the engine enforces it.
Northwind
Create your account
Start collaborating with your team in minutes.1
Work emailBy continuing you agree to our Terms and Privacy Policy. We'll email you a confirmation link.
mike@partner.co · #1 · change“In minutes” is a promise support will eat. Onboarding takes a day — say “today”.Your agent says what silence will cost
Not a notification, and not an open-ended wait. The ask declares what happens if nobody answers — and Mike is told the same sentence, word for word, because both come from the same place.
Kay Weissinger asks: “OK to ship this signup copy?”
Kay can’t continue without this. Unanswered by
Fri 5:00pm, it gets dropped.
He opens one link from his email. No signup, no password, no app — the question is at the top of the page he's being asked about, and two buttons are at the bottom.
Needs revision
Judgment comes back shaped, not as prose
One anchored note, one ready-to-apply diff, one ruling — paired with the ask, and pinned to the version he actually saw.
One blocker, one fix. Mike isn't arguing about the design — he's flagging a claim the product can't keep, which is exactly the kind of thing none of us can see from inside the repo.
Applying his wording and re-asking. Want to look before I do?
He clears it, and the work resumes itself
The gate resolves and your agent picks up exactly where it parked — doing the thing it told everyone it would do on a Ready. Whichever session is open, tomorrow or on another machine.
Two people, two agents, one Mike.
A second person doesn't break the asking. They break everything around it.
Mike gets asked twice.
Your agent asks him about the refund copy on Tuesday. Dana's agent asks him again on Thursday, because Dana's agent has no way of knowing yours ever did.
One trail across everybody's agents. Dana can see that Mike already ruled, what he wrote, and which version he was looking at when he wrote it.
The rule binds whoever remembered it.
Every ask declares what it is, and the declaring is done by whichever agent happens to be running. A rule half the team remembers is a habit, not a rule.
Set it once for the organisation — anything under
src/billing/** asks Mike, always required. The same hook
that refuses an edit until somebody rules reads your team's rules in
everyone's repo, and the rules page names anyone whose agent hasn't
picked them up yet.
Five people is five card charges.
Five accounts, five receipts to expense, five separate histories, and no way to look across them.
One organisation, one invoice, one roster you invite to by email. Reviewers still never sign up — that does not change, on any plan.
Free until it's a real business.
Reviewers never pay and never sign up, on any plan. However many people you ask, you are only ever billed for your own team.
$0
- The whole loop — share, ask, gate, pull
- HTML prototypes and prompts, text or markdown
- 50 reviews a month
- Unlimited reviewers, who never sign up
- The full activity trail, on screen and filterable
- 70+ agents, and the MCP server
A review is one ask you send. Reminders, receipts and expiry notices don't count against it.
$9 /mo · or $90/yr
- Unlimited reviews
- Feedback on live web apps
- Custom domains — as many as you need
- Slack responses
$40 /mo · or $400/yr
- 10 seats included, then $4 each, up to 100
- Everything in Pro, for each person on it
- One shared trail across everyone's agents
- Sign-off rules set once, not per ask
Call us
- Everything in Team
- SSO — your identity provider
- Unlimited seats
Setting it up is genuinely a conversation — your IdP, proving you own the domain, and a way in for when the IdP is down.
Ask for a value, not a paragraph.
Sometimes you don't need an opinion. You need a decision your agent can branch on.
Ask them to pick
Your agent generates alternatives constantly; picking is what people are
best at. Two to four options, about fifteen seconds, and it comes back as
{"choice":"b","because":"…"} — a value you branch on, not
prose you interpret.
Ask up to five things
Your agent writes the form, because it knows what it was unsure about. Five is the cap. Every question is optional, and there’s always a free-form field it didn’t write — where the thing it failed to ask about comes back.
A block that actually blocks
Skill text is a request a model can decline. In Claude Code, a hook runs outside the model and refuses the edit — scoped to the paths you named, overridable with a recorded reason. Everywhere else it degrades to advice, and says so.
Told in your own Slack
Paste one incoming-webhook URL and you get a line when somebody answers, when a deadline passes unanswered, and when an ask email bounces. Your workspace, your channel — and never a word the reviewer wrote, because they answered you, not your team.
They get their own copy, and we can’t reach it
After they answer, we email the reviewer what they wrote and a checksum of it. A checksum we compute and store proves nothing to anyone who doubts us — so the copy that counts is the one signed by our domain, timestamped by their mail provider, sitting in a mailbox we cannot touch. Quote them later and the same words produce the same checksum. Different words don’t.
Or reach it over MCP
Seven tools against the token you already have. MCP has no message addressable to anyone but the operator — so a tool call is the only way an agent reaches a third party, and this is that tool.
Six things we will not do.
Every one of these is a decision in the code, not a policy page.
Your agent's session never leaves your machine
We host the thing you deliberately shared, and nothing else. No transcripts, no context, no code you didn't publish.
Reviewers never sign up
No account, no password, no app — one durable link per person, where every ask you send stacks up.
Links are unguessable, and they expire
Gated by an email allowlist, or open to anyone with the link when you choose. Thirty days, then gone.
Every step is on the record
Who was asked, when it landed, who opened it, and what they said — word for word, with a checksum they also hold in their own inbox. Provenance, not a certified audit: we attest to what happened on our wire, never to what it meant.
We say how sure we are, and never more
Someone typed that address, or redeemed a link handed to them, or clicked one sent to their mailbox. Those are three different things and we label which. None of them is proof of identity, and you will never see us call it that.
Silence is never approval
An ask nobody answered is recorded as unopposed or abandoned — never as a yes. There is no setting that changes this, because there is no field that could hold it.
Stop pasting screenshots into Slack.
npx skills@latest add Brightwing-Systems-LLC/humangated-skills -g --skill '*'
One line, then run the loop from your agent. Why it works this way · read the skills · the agent setup page.