A tool declared effect=dangerous (or approval-required) must sit behind human_gate, and strict deploy refuses any ungated path to it. The gate has to be immediately before the effect on the same path: draft -&gt; human_gate -&gt; send. A gate in a sibling par branch or a child sub() does not dominate the parent path, so if your dangerous tool is reachable through any path that skips the gate, strict deploy rejects it. Also, do not put dangerous or approval-required tools directly in app(tools=[...]); that reports CAP_APP_APPROVAL_TOOL. Trace every path to the dangerous tool and make sure each one passes through a gate.

Context: Julep strict deploy rejects my flow with APPROVAL_UNGATED. I have a human_gate in the flow already. Why is it still complaining?