Approvals and autonomy
How much the goal's agent may do without asking, the rules behind it, where approvals reach you, and how change requests work.
You decide how much the goal's agent does on its own. One setting, Delegation, sets the overall level; rules for single tools fine-tune it; and anything that needs a person reaches you as an approval, a question or a change request. This page covers each, plus the limits that keep automated work in bounds.
How much it does on its own
During setup this is On its own in the goal brief. Later you change it with the Delegation control in the Overview header, or in Settings › Autonomy › Delegation.
| In setup | On the Overview | Actions in connected apps | Re-plans |
|---|---|---|---|
| Asks before acting | Ask first | Every call waits for your approval, reads included. | Every revision waits for you. |
| Acts within your rules | Within policy | Your connector rules decide. With no rules of your own, reads run and writes and deletes wait for you. | Revisions that only change tasks and check-ups apply at once. |
| Acts on its own | Act freely | Calls run without asking, writes and deletes included, unless one of your rules says otherwise. Connectors set to Ask before every use still ask. | Revisions that only change tasks and check-ups apply at once. |
A few things to know:
- A new goal stays at Ask first until you select Launch. Launch applies your choice, or Within policy if you made none.
- The level is stored as the goal's connector rules. The control shows what it means right now, for example "Now: calls that only read run on their own; writes and deletes wait for your approval." If someone edits the rules later, the control says so and shows where the goal stands.
- Moving from Ask first or Act freely back to Within policy restores the rules you had before.
- Only people who can manage connector rules can change the level.
- It does not change how the agent learns. That is the Learning setting on the same page; see Learning. Website logins and daily limits, below, also apply whatever the level.
Rules for single tools
Open Brain › Connectors, or select Edit connector rules in the Delegation control. There are two layers, and the first rule that matches a call decides:
- Global rules apply to every connector. Each matches a tool name pattern, such as
gmail.send_*, and is Allow (runs without asking), Ask first (waits for your approval) or Block (never runs, and the agent cannot see it). - On a connector's own page, each tool is Default, Block, Ask or Allow. The Ask before every use switch makes every tool of that connector ask, reads included, unless a rule opens one. Use it for mail, files or anything where reading is itself sensitive.
A call no rule covers follows the goal's default: Ask before risky actions (reads run, writes and deletes ask) or Run everything. See Connectors.
Where approvals reach you
When a rule asks first, the agent pauses that step and asks. You can decide in any of these places, and the first decision counts everywhere:
| Where | What you see |
|---|---|
| Chat | A Needs your approval card pinned above the composer: the app and action, its risk (read, write or destructive) and the exact values, with Approve and Deny. |
| Overview › Needs you | An Approval card with Approve, Deny and the ⋯ menu (More choices). |
| Review Center | Brain › Review lists every approval. Open one to see its full values before you decide. |
| Your channels | The approval also goes to the Slack, Teams, iMessage or email conversation the request came from, or where the schedule reports. In Slack and iMessage, a message the agent wants to send arrives as the draft itself, ending with "Go?": reply go to send it, no to stop it, or say what to change. |
| An approval page | Each approval has its own page at a link like /approve/<token>, opened from Open approval page on the card. Sign in, check the values and decide. The decision covers that one call. |
If nobody decides in the app, Escalate what needs you can forward it after a delay; see Plans, schedules and triggers.
Only a signed-in person can decide. An agent never approves its own call, whatever access it has. A call that recorded no values can only be denied.
Approve and make it a rule
On an Approval card in Needs you, open the ⋯ menu (More choices) and select Approve and make it a rule. This approves the call and adds an Allow rule for that exact action at the top of the global rules, so it runs without asking from now on. It needs the right to manage connector rules. If the rule cannot be saved, the approval still stands and a message says so.
Scheduled actions approved in advance
When the agent sets a routine that repeats one gated action, such as posting a weekly summary to a channel, it can ask you to approve that action once, when it sets the schedule. Later runs then carry out exactly that action without a new card. Anything different still asks.
Questions
When the agent needs a decision or a fact, it asks. In Chat the question is pinned above the composer: pick an option, type your own under "Something else…", or select Skip to let it continue without an answer. If the question went to a channel, reply in that conversation and your reply answers it. A task agent never asks you directly; the goal's agent asks in Chat on its behalf.
Change requests
A change request is a proposed change to the goal's repository: its plan, instructions, skills, memory, settings or code. It waits on a separate branch until a person approves it, so nothing in it takes effect before that. Each one records who proposed what and who approved it, and you can send it back with a note.
| What goes through a change request | Where it shows up |
|---|---|
| A new or revised plan that waits for you | A Plan card in Needs you, and a card in Chat |
| Work from a Coder task | Review change request #… on the task card |
| Changes learning proposes that need you, such as replacing memory or editing a skill a person wrote | Brain › Learning › Needs your decision, Needs you on the Overview and the Review Center |
| An item you make with Create in chat in the Brain, such as a trigger or a skill | Needs you and the Review Center |
Open a change request from Needs you or from the Review Center at Brain › Review. You see what was proposed, the changed files and, when there is one, the session that made it. Then:
- Approve applies it. For a plan the button is Approve plan. Approving needs permission to merge changes on the goal.
- Request changes (Ask for changes in the Review Center) asks what should change. For work that came from a session, Send to the agent hands your note over and the agent revises the same change request; otherwise the note is saved on it.
- Dismiss in the Review Center closes it without applying anything.
- If the change conflicts with newer work, or would break the goal manifest, Fix with the agent starts an agent that resolves it and opens a replacement.
A change request is Waiting on you, Applied or Dismissed. An agent can open change requests but never applies its own: the session that opened one cannot merge it, whatever permissions it holds. A re-plan that only changes tasks, under Within policy or Act freely, is applied by Auto Lab under your rules, not by the agent.
Action audit
Settings › Autonomy › Action audit lists connector actions and approval decisions. Filter by result: Awaiting approval, Succeeded, Denied or Failed. Request values and secrets are never shown. The history needs audit access for your organization; without it the card says so, and your approval rules still apply.
Automation limits
The Automation card in Settings › Autonomy caps how much automated machine work the goal starts each day.
| Setting | Default | What it limits |
|---|---|---|
| Sandbox minutes per day | 120 | Machine time used by sessions and by task agents that need a machine of their own |
| New sessions per day | 20 | Sessions started in a day. Reusing a session that already exists still works. |
The card shows today's use, and people who manage the goal's triggers can change the limits. Limits reset at midnight UTC. At a limit, the card says Paused: daily automation budget reached or Daily session limit reached, and new automated work that needs a machine does not start: a scheduled trigger skips its run, and a task agent that needs its own machine reports that the daily budget is used up. Sessions already running finish. Conversation in Chat, and task agents that need no machine, carry on.
Approve website login use
The Approve website login use switch sits on the same card. When it is on, the first time an agent uses a saved website login in a session, it asks for your approval. One approval covers that login for the rest of that session. Only people who can manage the goal's secrets can change it. See Website logins and secure links.