Marking an operation request creates a durable approval record and keeps the
original call open. Once approved, a git push resumes as the same push. A
denial, expiry, or change in upstream state returns an ordinary Git failure and forwards
nothing.
Operators decide through a protected inbox on a separate listener with its own credential. Telegram can display the same approval record. Either interface closes the request exactly once, and approval may only narrow its duration or use count.
How approvals work