The review queue.
One page holds everything waiting on you, across every project, and ranks what is worth doing next. Cyboflow opens on it. Findings are the exception: they are triaged in Insights, and only a blocking one shows up here.
01The landing page
Human review is the app’s landing surface, not a side pane you open. The header reads Human review queue over a count of what is waiting: pending permission approvals, review items, runs ready for review, quick sessions needing attention, and blocked runs.
The left-rail item, labeled Human review with the subtitle Pending approvals, carries a live badge and brings you back here, scrolled to Needs your input. ⌘R opens it from anywhere, and ⌘L opens the task backlog. On Windows, press Ctrl in place of ⌘.
- Needs your input is the red band for things that have halted on you: blocked quick sessions, decision items, and live permission approvals. Each row carries an “Asked you” kicker, a quiet 12m age, the project, and the worktree branch behind the ask. The session name joins them once you have renamed the session, so you know which one is stopped before you open it.
- Blocked is the amber band for halted runs that no other band already lists. Its only action is Open →.
- Ready for review is the band of finished work. It shows three rows and hides the rest behind a toggle. A quick-session row expands to Merge to main, Open session, and Dismiss session; a drained flow run expands to Open session alone. The button says main, but the merge goes to the project’s effective default branch: see merge, PR, dismiss. Merge and Dismiss are withheld while the session is one arm of a live A/B experiment.
- Working is one row per live agent, with a flow run and the session hosting it folded into a single row.
- Notifications sits under Ready for review and offers Dismiss, nothing else.
02The five item kinds
Blocking is a property of each item, set when the item is filed. An item is non-blocking unless the agent that files it asks for blocking. Permission and decision items are filed blocking by convention; a notification is refused blocking outright.
Clearing a blocking decision resumes the paused run only when no other blocking item for that run is still pending. Until then the run waits.
Every verdict on this page is a button, and the queue has no triage keystrokes of its own.
03Decision gates
Answer → carries you into the run, where the gate lives, rather than answering it here.
A gate renders as an inline card inside the run’s chat transcript, in a flow run and in a quick session alike, and you answer it from the composer. It never lands in the permission list, so an empty approvals list is not proof that nothing is waiting on you.
The run view also carries a pending-input strip along its footer, listing that run’s pending items and live questions. That strip is where Approve & resume, Reject, and the idea-size guard’s buttons live, not on the queue. See run controls.
- Gates are durable. One survives the underlying SDK session expiring, and it survives an app restart.
- A gate lost with its session comes back as a recovery item that must be answered through its own control. Ordinary Approve and Reject are refused for it, and an answer that cannot be delivered leaves the card open with the reason, such as the run being busy and needing to settle first
- A queue card for a gate reads Human gate: <step name>, so the same gate can carry two names depending on where you answer it.
- A pending approval card in the run names the session that is asking, with a badge for the provider behind it, so a Claude ask reads differently from an OMP one. It stops short of full attribution: it cannot pick out one lane of a five-lane Sprint, because all five sit in the one session.
- A Codex question flagged secret renders as a masked field and is stored redacted rather than in cleartext.
04Acting from the queue
Recommended actions is the one band that ranks its cards. At most six show at once, drawn from nine kinds, session triage first and flow launches after. Anything past six hides behind a +N more ▾ row.
- Review & merge opens the session. The merge itself happens inside it, from the session’s own Merge, Create PR, and Dismiss controls: see merge, PR, dismiss.
- Every card except the headline Review now card carries Dismiss. A dismissal is keyed to that card’s evidence, so the card returns as soon as the sessions, tasks, or findings behind it change.
- Wrap up fires only once a finished session has been quiet for more than 72 hours.
- Launch sprint needs at least three tasks at Ready for development and no sprint already running in that project.
- Run Launch is hidden for an established codebase. It appears only for a project whose repository has no real commit history and nothing on the backlog.
The Backlog section at the foot of the page is a launcher rather than a list. It gives you two columns to pick from, Top ideas and Next up · Ready for development, with Launch planner → (four ideas at most) and Launch sprint →. A selection is locked to one project.
Add an idea opens a one-question capture box, plus a project picker when you have more than one project, and then offers to run Planner on what you wrote.
05Provider usage meters
The page opens on subscription headroom for each of Claude and Codex you have enabled. OMP is not metered here, so it has no card. What you unblock next depends on whether there is quota left to run it, and a lane parked on an exhausted window looks the same as a lane waiting on a person.
- One row per quota window, each with its own reset countdown. A window shows a used percentage, or a status word of OK, Watch, Low, or Exhausted when the provider reported no number. The windows expire on unrelated clocks, so one can be exhausted while another is still fresh.
- A card can carry more than one row per window: per-model weekly buckets such as Weekly (Opus), and an Extra usage row that is hidden for an account with none.
- Codex always reports a used percentage. Claude reports utilization only sometimes, so a window with no percentage shows an empty track and its status word rather than 0%.
- A percentage read from a running turn rather than a direct query is flagged may be stale, because it only refreshes when a turn happens to run. A card whose last reading is more than 30 minutes old says it has no recent reading.
06Customizing the queue
The review queue and the project overview are the only two surfaces you can rebuild. The board keeps its fixed layout.
Both headers carry a view switcher (Default, plus any view you have saved, with Manage views… in its footer) and a Customize button that opens a draft.
- In the draft, every block grows grip, eye, gear, and trash controls. A hidden block stays on screen as a collapsed row so you can bring it back.
- Commit with Save or Save as…, or throw the draft away with Discard or Escape.
- + Add widget opens a library grouped into Sections, Insights, Stats, Lists, and Mine. A section already placed in the draft is shown grayed out, its button reading Added, so you can see why it cannot be added twice.
- Create a custom widget expands the assistant rail and pre-fills the composer with a kickoff message you send yourself, rather than opening a form.
A custom widget is capped at four data sources, six actions, and 500 rows, and refreshes no faster than every 15 seconds: 60 seconds by default, 1 hour at the slowest. Saving one to your own library is the single assistant write that needs no confirm card, and the assistant page covers the rest.