cancel_workflow
Cancel a workflow to prevent execution after an approval is rejected or a plan is deemed unsafe. Preview the blast radius first, then confirm to permanently stop future steps.
Instructions
[WRITE] Cancel a workflow — move it to the terminal CANCELLED state.
Use this when an approval is REJECTED, a review flags the plan as unsafe, or an operator decides the workflow must never run. A cancelled workflow is dead: run_workflow and approve refuse to execute it. Without this, an approval-rejected PENDING workflow could still be picked up and run.
Without confirm=True this only previews: it returns blast_radius — the workflow's id, type and state, the executed steps that stay applied (left_in_place: cancelling part-way leaves a half-applied change), the steps that would be skipped (would_skip), steps with unknown effects, and blockers — and changes nothing. Show that to the user and get their explicit decision. Do not set confirm=True on your own because the user asked to cancel earlier — the user has not seen the preview yet.
Cancel only stops FUTURE steps. It does NOT undo already-completed steps — use rollback() to reverse those. Refused with confirm=True: an already completed/failed/cancelled workflow, a step whose status Pilot does not recognise, a workflow record that cannot be read, and — unless acknowledge_unknown_effects=True — a step left 'running' or 'interrupted' (listed in unknown_effects). The cancellation is written to the workflow audit log.
Returns: Preview: {"action": "preview", "blast_radius", "hint"}. Acting: the workflow state (state='cancelled', outcome='cancelled', action='cancelled') with blast_radius, or an error if refused.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| reason | No | Optional human-readable reason (e.g. "approval rejected by on-call"), recorded in the audit log. | |
| confirm | No | False (default) returns the blast radius and changes nothing. True applies it. | |
| workflow_id | Yes | The workflow ID to cancel. | |
| acknowledge_unknown_effects | No | Set True only after the user has checked, in the target system, whether each unknown_effects step took effect. Covers only those steps; every other refusal still applies. |