Skip to documentation
DocumentationApprovals

Approvals, grants and access requests

Review a waiting call, choose how long permission lasts, and handle missing access.

On this page

Open Approvals to review calls waiting for a person. A card shows the agent, binding, service target, action class and requested operation. The agent waits until you decide or the approval expires.

Review and answer a card

  • Check the agent, service, method, path and class before approving. Use History to find decisions already made.
  • Choose Approve or Deny. A denial needs a reason; a destructive approval needs a reason and the requested second-factor check.
  • A submitted decision is final for that card. A denial is returned to the agent with the reason, so replaying the same call will not ask again.

Choose the permission scope

ChoiceWhat it does
OnceApproves this waiting call only.
GrantApproves the call and creates a time- and call-limited grant for its agent and binding. A policy that denies the action class still blocks a grant.
AlwaysChanges this binding’s policy for the action class from ask to auto. An owner or admin must choose it; it writes a policy change, not a grant.

Review active and expired permissions in Grants, and review class rules in Policies. A grant is tied to an agent and binding; policy changes can revoke grants that no longer fit the policy.

Continue a waiting call or handle expiry

While a card is pending, have the client retry the same operation with its existing call_id. That resumes the same call; it does not start another one. After approval, the same call returns its result. After denial, the same call_id keeps the denial. If the card expires, the operation was not dispatched: submit it again without the old call_id to create a new request.

Set up access the agent does not have

An approval answers a call that already has a usable binding. For a missing binding or credential, open Access requests. Review why it was raised, then grant the service access the agent needs. Paused bindings, retired credentials and expired grants are also shown there.

Choose where approval cards notify you

Open Notifications. To link Telegram, choose Connect Telegram, then open the bot and press Start or send its one-time /start code in a private chat. Choose which Read, Write and Destructive cards send a notification.

Enable browser notifications on this page to receive cards in this browser. If notifications are blocked, allow them in the site settings beside the address bar and reload. Email to the account address is the backup channel; this page has no separate email-recipient field. Use Send a test card after linking Telegram.