The agent proposed an action. Nothing executes until a human mints a signed warrant here.
PROPOSED ACTION (from the orchestrator)
Demo signs with a shared DEMO-OPERATOR-KEY. In production the
operator key lives only in this approval surface and the MCP boundary — never in the agent.
SIGNED WARRANT (paste into the boundary to authorize this one action)
Without this warrant, execute_remediation raises ApprovalRequired.