Production
Live Case study

EQMO

Human-in-the-loop document approval for AI agents. An agent writes a document and submits it over REST or a hosted MCP server; a human approves, rejects, or sends it back with comments anchored to the exact text. Every version is immutable and every decision is recorded.

PlatformWeb · REST · MCP StatusLive CoreApproval loop StackNext.js · REST API · MCP server

01Problem

AI agents can write documents, but letting them publish, send, or act on those documents unsupervised is risky. Teams want agents in the workflow and a human making the final call — without that review turning into untracked approvals buried in email threads and chat.

The problem was to put a reliable, auditable approval gate between an agent’s output and the real world: an agent submits, a human decides, the agent reads the decision and iterates — with a record that can be trusted after the fact.

02Product

EQMO is a document registry and review system built for the agent loop. Agents submit documents through scoped API keys over REST or the hosted MCP server. Reviewers get a one-time email link, read the rendered markdown, highlight and comment on exact passages, and decide: approved, approved with comments, or changes requested. The agent reads the decision and resubmits a new version, which restarts approval from the first step.

03Architecture

04Engineering decisions

Why a hosted MCP server, not just REST?

MCP lets agents in tools like opencode and Claude connect to approvals, documents, and projects natively. The same capabilities are exposed over REST, so integration doesn’t depend on a single client.

Why scoped keys that can’t approve?

Agents get eq_ keys scoped to read, write, and submit — never to approve. The authority to ship a document stays with a human by construction, not by policy.

Why immutable, hashed versions?

Each submission is stored immutably, SHA-256 hashed, and numbered. You can diff any two versions and prove exactly what was reviewed and approved, with no silent edits after the fact.

Why restart approval on every new version?

A new version always restarts the chain from the first step. Nothing carries over, so an approval can never slip through on wording that changed in a later revision.

How are comments kept meaningful across versions?

Comments anchor to a highlighted passage and re-anchor when a new version shifts the surrounding text, so reviewer intent survives edits instead of detaching.

How is the record made trustworthy?

Every submission, comment, decision, and login is appended to a hash-chained log per organization. Any edit would break the chain, so the audit trail is tamper-evident.

What stops silence from blocking the loop?

Each step can carry an auto-approval window or an SLA sweep that nudges overdue reviewers by email, so a stalled review has a deadline rather than stalling the agent indefinitely.

How is reviewer feedback enforced downstream?

When a document is approved with comments, the next version must carry those comments in a generated annex block; the API rejects submissions that drop it, so feedback can’t be quietly discarded.

05Implementation

  • Agent interface — a REST API and a hosted MCP server exposing documents, submissions, and decisions, authenticated with scoped, shown-once keys.
  • Versioning — immutable, SHA-256-hashed, sequentially numbered document versions with version-to-version diffs.
  • Review — markdown rendering, text-anchored comments, and configurable approval chains (serial or parallel, ordered by role).
  • Audit — an append-only, hash-chained event log per organization covering submissions, comments, decisions, and logins.
  • Access control — roles (admin, editor, viewer, approver, external) and key scopes that separate agent submission from human approval.
  • Web app — built on Next.js, with a dashboard for the reviewer queue and the document registry.

06Production

  • Live at eqmo.com with a hosted MCP server and REST API.
  • Published OpenAPI reference and agent/MCP setup documentation.
  • Tiered plans with account sign-up, API-key management, and per-organization isolation.
  • Email-based reviewer access with one-time links — no password required for external approvers.

07Current status

Live production   Available at eqmo.com, with documentation for the REST API and the hosted MCP server.