# Approvals and autonomy

How much the goal's agent may do without asking, the rules behind it, where approvals reach you, and how change requests work.

Canonical page: https://app.auto-lab.ai/docs/goals/approvals

You decide how much the goal's agent does on its own. One setting, **Delegation**, sets the overall level; rules
for single tools fine-tune it; and anything that needs a person reaches you as an approval, a question or a
change request. This page covers each, plus the limits that keep automated work in bounds.

## How much it does on its own

During setup this is **On its own** in the goal brief. Later you change it with the **Delegation** control in
the Overview header, or in **Settings › Autonomy › Delegation**.

| In setup | On the Overview | Actions in connected apps | Re-plans |
|---|---|---|---|
| **Asks before acting** | **Ask first** | Every call waits for your approval, reads included. | Every revision waits for you. |
| **Acts within your rules** | **Within policy** | Your connector rules decide. With no rules of your own, reads run and writes and deletes wait for you. | Revisions that only change tasks and check-ups apply at once. |
| **Acts on its own** | **Act freely** | Calls run without asking, writes and deletes included, unless one of your rules says otherwise. Connectors set to **Ask before every use** still ask. | Revisions that only change tasks and check-ups apply at once. |

A few things to know:

- A new goal stays at **Ask first** until you select **Launch**. Launch applies your choice, or **Within policy**
  if you made none.
- The level is stored as the goal's connector rules. The control shows what it means right now, for example
  "Now: calls that only read run on their own; writes and deletes wait for your approval." If someone edits the
  rules later, the control says so and shows where the goal stands.
- Moving from **Ask first** or **Act freely** back to **Within policy** restores the rules you had before.
- Only people who can manage connector rules can change the level.
- It does not change how the agent learns. That is the **Learning** setting on the same page; see
  [Learning](/docs/brain/learning). Website logins and daily limits, below, also apply whatever the level.

## Rules for single tools

Open **Brain › Connectors**, or select **Edit connector rules** in the **Delegation** control. There are two
layers, and the first rule that matches a call decides:

1. **Global rules** apply to every connector. Each matches a tool name pattern, such as `gmail.send_*`, and is
   **Allow** (runs without asking), **Ask first** (waits for your approval) or **Block** (never runs, and the
   agent cannot see it).
2. On a connector's own page, each tool is **Default**, **Block**, **Ask** or **Allow**. The **Ask before every
   use** switch makes every tool of that connector ask, reads included, unless a rule opens one. Use it for mail,
   files or anything where reading is itself sensitive.

A call no rule covers follows the goal's default: **Ask before risky actions** (reads run, writes and deletes ask)
or **Run everything**. See [Connectors](/docs/connect/connectors).

## Where approvals reach you

When a rule asks first, the agent pauses that step and asks. You can decide in any of these places, and the
first decision counts everywhere:

| Where | What you see |
|---|---|
| Chat | A **Needs your approval** card pinned above the composer: the app and action, its risk (read, write or destructive) and the exact values, with **Approve** and **Deny**. |
| **Overview › Needs you** | An **Approval** card with **Approve**, **Deny** and the **⋯** menu (**More choices**). |
| Review Center | **Brain › Review** lists every approval. Open one to see its full values before you decide. |
| Your channels | The approval also goes to the Slack, Teams, iMessage or email conversation the request came from, or where the schedule reports. In Slack and iMessage, a message the agent wants to send arrives as the draft itself, ending with "Go?": reply **go** to send it, **no** to stop it, or say what to change. |
| An approval page | Each approval has its own page at a link like `/approve/<token>`, opened from **Open approval page** on the card. Sign in, check the values and decide. The decision covers that one call. |

If nobody decides in the app, **Escalate what needs you** can forward it after a delay; see
[Plans, schedules and triggers](/docs/goals/schedules#escalate-what-needs-you).

Only a signed-in person can decide. An agent never approves its own call, whatever access it has. A call that
recorded no values can only be denied.

### Approve and make it a rule

On an **Approval** card in **Needs you**, open the **⋯** menu (**More choices**) and select **Approve and make it a rule**. This
approves the call and adds an **Allow** rule for that exact action at the top of the global rules, so it runs
without asking from now on. It needs the right to manage connector rules. If the rule cannot be saved, the
approval still stands and a message says so.

### Scheduled actions approved in advance

When the agent sets a routine that repeats one gated action, such as posting a weekly summary to a channel, it
can ask you to approve that action once, when it sets the schedule. Later runs then carry out exactly that action
without a new card. Anything different still asks.

## Questions

When the agent needs a decision or a fact, it asks. In Chat the question is pinned above the composer: pick an
option, type your own under "Something else…", or select **Skip** to let it continue without an answer. If the
question went to a channel, reply in that conversation and your reply answers it. A task agent never asks you
directly; the goal's agent asks in Chat on its behalf.

## Change requests

A **change request** is a proposed change to the goal's repository: its plan, instructions, skills, memory,
settings or code. It waits on a separate branch until a person approves it, so nothing in it takes effect before
that. Each one records who proposed what and who approved it, and you can send it back with a note.

| What goes through a change request | Where it shows up |
|---|---|
| A new or revised plan that waits for you | A **Plan** card in **Needs you**, and a card in Chat |
| Work from a Coder task | **Review change request #…** on the task card |
| Changes learning proposes that need you, such as replacing memory or editing a skill a person wrote | **Brain › Learning › Needs your decision**, **Needs you** on the Overview and the Review Center |
| An item you make with **Create in chat** in the Brain, such as a trigger or a skill | **Needs you** and the Review Center |

Open a change request from **Needs you** or from the Review Center at **Brain › Review**. You see what was
proposed, the changed files and, when there is one, the session that made it. Then:

- **Approve** applies it. For a plan the button is **Approve plan**. Approving needs permission to merge changes
  on the goal.
- **Request changes** (**Ask for changes** in the Review Center) asks what should change. For work that came from
  a session, **Send to the agent** hands your note over and the agent revises the same change request; otherwise
  the note is saved on it.
- **Dismiss** in the Review Center closes it without applying anything.
- If the change conflicts with newer work, or would break the goal manifest, **Fix with the agent** starts an
  agent that resolves it and opens a replacement.

A change request is **Waiting on you**, **Applied** or **Dismissed**. An agent can open change requests but never
applies its own: the session that opened one cannot merge it, whatever permissions it holds. A re-plan that only
changes tasks, under **Within policy** or **Act freely**, is applied by Auto Lab under your rules, not by the
agent.

## Action audit

**Settings › Autonomy › Action audit** lists connector actions and approval decisions. Filter by result:
**Awaiting approval**, **Succeeded**, **Denied** or **Failed**. Request values and secrets are never shown. The
history needs audit access for your organization; without it the card says so, and your approval rules still
apply.

## Automation limits

The **Automation** card in **Settings › Autonomy** caps how much automated machine work the goal starts each day.

| Setting | Default | What it limits |
|---|---|---|
| **Sandbox minutes per day** | 120 | Machine time used by sessions and by task agents that need a machine of their own |
| **New sessions per day** | 20 | Sessions started in a day. Reusing a session that already exists still works. |

The card shows today's use, and people who manage the goal's triggers can change the limits. Limits reset at
midnight UTC. At a limit, the card says **Paused: daily automation budget reached** or **Daily session limit
reached**, and new automated work that needs a machine does not start: a scheduled trigger skips its run, and a
task agent that needs its own machine reports that the daily budget is used up. Sessions already running finish.
Conversation in Chat, and task agents that need no machine, carry on.

### Approve website login use

The **Approve website login use** switch sits on the same card. When it is on, the first time an agent uses a
saved website login in a session, it asks for your approval. One approval covers that login for the rest of
that session. Only people who can manage the goal's secrets can change it. See
[Website logins and secure links](/docs/connect/website-logins).
