In the console (hosted plans, or self-hosted Enterprise): the “To approve” screen, in the main navigation.
On the command line (free self-host): kastel moderation list, show, approve, reject.
The queue itself is not conditioned by any plan. What plans open is multi-person approval: see section 04.
One queue, one card, one choice
Everything awaiting a decision lands in the same place, in the same grammar: a plain-English question, the excerpt that serves as proof, and two buttons. The primary verb is always “Approve”; the second one says what “no” means - decline a decision, correct a stale fact.
What lands in this queue today:
- A source to confirm for good, when someone asks that it count as verified.
- A proposed page edit, from a person or from an AI.
- A statement your Kastel picked up and proposes to add to a page.
- A contradiction: two pages disagree, and you choose which one holds.
- A weekly-check question: confirm a fact is still current, or correct it in one sentence.
- A lesson proposed by an AI from its own work - approving it writes nothing, it records that a human reviewed it.
- Maintenance signals: a cited source that vanished, pages started and never finished, two pages saying almost the same thing, a dropped document that found no home.
Everyone sees only what concerns them: the queue is filtered by the reader's scope and role.
What approving means: all or nothing
A proposal applies entirely, or not at all. There is no in-between state where half an edit landed. Declining changes nothing whatsoever: the page stays as it was, and the refusal is recorded.
Every change that lands in your Kastel carries its author's name and its date - whether it came from a person, a dropped document or an AI. That attribution, not a technical log, is what answers “who wrote this, and when”. The record you can put in front of an auditor is your instance's sealed audit chain.
An AI plugged into your Kastel does not bypass this path: when it proposes an edit, it files a proposal in this queue exactly as a person would, and nothing changes until someone approves.
Rolling back
A rollback does not erase history: it is one more operation, itself dated and attributed. Your Kastel therefore keeps a trace of the change and of its undoing, which is exactly what an auditor wants to see.
This holds for the two things that get undone: a page edit, and a governance change. On a “who decides” change, the “Undo this change” button restores the previous state, revalidated and audited on the way. On the command line, that is kastel aor revert.
Approving as a group
Simple approval - one person decides, directly - is in the free core, unconditionally. What plans open is splitting the decision across several people.
| Mechanism | What it does | Included from |
|---|---|---|
| Decision queue | Everything awaiting a decision, filtered by scope and role | free core |
| Approval rules | Who must approve, in what order. A request follows its rule, step by step | Kastel Equipe |
| Separation of duties | You never decide your own request: someone else has to | Kastel Equipe |
| Manual escalation | “Not mine to decide”: the request goes back to whoever it belongs to | Kastel Equipe |
| Auditor role | A dedicated read-only seat, for whoever must check without acting | Kastel Equipe |
| Cross-department chains | A rule that chains approvers across several departments | Kastel PME |
A single-step rule is enough to start, and it is already real governance: someone is named, and they decide.
If nobody answers
A request left unattended does not evaporate and never self-approves. It escalates to leadership: that is the default, and it is also what happens when a department has no head named.
The corollary is worth stating the other way round: nothing applies because nobody answered. An absent decision is never a decision, in either direction.