When an approval is created
- Risky tool calls. Tool calls are classified automatically (outbound, destructive, escalation). Safe calls run directly; risky ones create an approval request and pause the run.
- Agent Decision Bounds. Each agent’s guardrails (“ask me before spending more than $X”, “ask me before doing something irreversible”) — see Agents.
- Mission human-approval steps. A mission flow can contain explicit approval gates — see Missions.
- Shared saves and proposals. Agents proposing to save company knowledge, update a skill, or hire an agent.
- MCP write tools. MCP servers with “Require approval for writes” enabled route write actions through approval.
Where you decide
What happens after you decide
- Approve — the system executes exactly the approved action (the tool and parameters shown in the “On approve” card), nothing more.
- Reject — the agent receives a follow-up with your rejection (and reason, where applicable) so it can adjust course.
- Every request has an expiry; overdue requests are marked expired.
- Escalations with high priority also raise a toast notification in the app the moment they arrive, with an Open action jumping to your Inbox.
Who may decide
- Company Admins can decide any approval.
- Members can decide approvals from agents they can see.
- Mission approvals follow the mission’s rules: the step’s designated approver, the owner, or a lead.
