Julep APPROVAL_UNGATED: dangerous tool not behind human_gate
A tool declared effect=dangerous (or approval-required) must sit behind human_gate, and strict deploy refuses any ungated path to it.
A tool declared effect=dangerous (or approval-required) must sit behind humangate, and strict deploy refuses any ungated path to it. The gate has to be immediately before the effect on the same path: draft -> humangate -> send. A gate in a sibling par branch or a child sub() does not dominate the parent path, so if your dangerous tool is reachable through any path that skips the gate, strict deploy rejects it. Also, do not put dangerous or approval-required tools directly in app(tools=[...]); that reports CAPAPPAPPROVAL_TOOL. Trace every path to the dangerous tool and make sure each one passes through a gate.
Context: Julep strict deploy rejects my flow with APPROVALUNGATED. I have a humangate in the flow already. Why is it still complaining?
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.