Inspiration
A product specification, an approved formula, and a certificate of analysis can disagree, and they often do. The specification still names formula revision 2 while the master formula is already revision 3. The certificate reports a pH the specification does not allow. A human reviewer can see that if the three PDFs are on one desk. An agent usually cannot: it scrapes a UI, invents a side channel, or silently edits the wrong bytes.
WebMCP is the missing control surface. The page should be the MCP server. The agent should call the same actions the reviewer sees, on the same documents, with the same results. Checks should not live in the frontend. Approvals should bind to digests, not to a screenshot of a button.
That is the inspiration for PDX ReviewDesk: one tab where humans and agents share a regulated dossier, while published ProDocuX and PDX Artifact Engine do the work the page must not invent.
What it does
As a MVP showcase, ReviewDesk is a WebMCP workspace for dossier review. The live demo is Harbor Calm Serum: the product specification is the subject; the formula and certificate are references.
The page walks Documents → Findings → Corrections → Close.
- Start the demo. ProDocuX verifies a typed evidence bundle and flags the planted disagreements (formula revision, pH range). PDX opens a digest-bound checkpoint.
- The agent focuses a finding and opens the governing source PDF in the same tab.
- A correction rewrites normalized evidence only. Source PDF bytes and digests never change. Commit re-runs ProDocuX and replaces the PDX checkpoint.
- An observed fact (the pH) can be confirmed without rewriting the certificate. Human-only approval stays on the UI. There is no WebMCP tool that approves the checkpoint.
Registered tools include start_demo_audit, get_workspace_state,
select_finding, open_source_document, propose_correction,
commit_correction, and confirm_observed_fact. execute() hits the same
FastAPI routes the page uses, so the workspace updates in place.
No login. Judges can open https://pdx-reviewdesk.onrender.com/ in ChatGPT’s in-app browser or in Chrome 149+ with WebMCP testing enabled.
How we built it
The UI is Vite and React. On every run-state change it aborts the previous
registration and calls document.modelContext.registerTool for the tools
that are currently enabled. Each tool’s execute() function is a real
workspace mutation, not a prompt that describes the UI.
The API is FastAPI. It consumes published PyPI packages:
prodocux==0.3.0rc4forverify_evidence_bundlepdx-artifact-engine==0.3.0a4for checkpoint open/replace and the approval ledger
GET /health publishes those installed versions. CI asserts they load from
site-packages.
Authorization does not trust JSON actor or channel. The page session
cookie plus a capability header decide whether a call is treated as UI or
WebMCP. Human-only approval at the current demo is a channel boundary, not cryptographic proof
that a person pressed the button.
The hosted app is one Python process that serves /v1, /health, and the
built SPA on Render.
Challenges we ran into
Keeping WebMCP honest was harder than registering tools. If execute()
does not change the page, the agent is just narrating. If the API trusts a
body field named actor, the agent can pretend to be the human. We had to
make the session cookie and capability header the only authorization, and
keep approval off the tool catalog.
Render’s Free plan does not attach a disk, so runs are ephemeral and the service spins down when idle. That is acceptable for judging. It is not how a durable review desk would store an approval ledger.
Accomplishments that we're proud of
- A WebMCP tool call updates the same documents, findings, and checkpoint the human is looking at.
- Verification and digest-bound checkpoints come from published products, not from a page-local reimplementation.
- Source PDFs are immutable. Corrections cannot launder a new file in as the original.
- The tool surface cannot approve. The human gate is visible and boring, which is what we wanted.
- The live URL, public Apache-2.0 repository, and
/healthpins are all checkable without a login.
What we learned
WebMCP is not a second kernel. It is how an agent holds the same desk as the human. The valuable tools are state-dependent: you cannot commit a correction that does not exist, and you should not be able to approve through the agent channel.
On the other hand, the security claim is important. A channel boundary is not a hardware attestation. It has to be emphasized before talking about “human in the loop.”
What's next for PDX ReviewDesk
Review is the first slice, not the final product. The desk should become a place where humans and agents co-author the packet, not only argue about PDFs that already exist.
Next, an agent will fill important documents from files the human names or from search results it is allowed to use. The human stays on the same page, watches the draft appear, corrects it, and accepts it. When the packet is agreed, ReviewDesk exports the specified formats - the durable path for verification and digest-bound artifacts is already the published ProDocuX and PDX Artifact Engine stack.
The review tools stay. They become the acceptance pass over a jointly written dossier, instead of the whole story.
Built With
- chatgpt
- docker
- fastapi
- github-actions
- javascript
- node.js
- openai
- pdx-artifact-engine
- prodocux
- pydantic
- pypdf
- python
- react
- render
- typescript
- uvicorn
- vite
- webmcp
Log in or sign up for Devpost to join the conversation.