Permissions and approvals
Set capability boundaries and review proposed actions before they execute.
Three permission modes
Permissions are evaluated by server code. The model can propose an action, but it cannot grant itself access. Machine settings, workspace restrictions, tool availability, and run approvals participate in that decision.
DENY blocks a capability. ASK pauses work for an operator decision. ALLOW permits the capability within the remaining checks and execution limits. Tool-specific restrictions can still require approval, including external writes without a configured domain allow-list.
- Network reads and memory writes are allowed in the conservative default configuration.
- Network writes and Machine delegation ask for approval by default.
- External communication, financial actions, code execution, and self-modification are denied by default.
Read the proposed action
An approval is attached to the proposed tool call and its arguments. Inspect the destination, payload summary, purpose, and risk before approving. Decide based on the action that will execute, rather than the apparent confidence of the model's explanation.
A one-time approval is narrower than a run-wide grant. Permanent approval from the approval card is available only for selected permissions such as network reads, memory writes, and Machine calls. Other permanent changes belong in the Machine's configuration.
Understand recovery
Approval state and tool results are persisted. Recovery can complete unanswered calls and reuse completed results after a process interruption.
If a tool was interrupted and its external outcome is unknown, the run stops instead of replaying an action that may already have happened. Check the destination and reconcile its state before manually starting similar work. This boundary matters most for writes and messages.
Scope access deliberately
Enable only the tools needed for the objective, restrict destination domains where supported, and keep external actions behind review during evaluation. Store integration credentials through the server-side integration flow.
Permission checks help constrain execution. They do not certify the correctness of model output or eliminate the need to evaluate the external system receiving an action.