When a tool needs human consent, the turn pauses until you decide.
Runtime cards
Each pending tool shows:
Allow once — run this call only
Allow for session — remember for this chat tab
Always allow — save a durable grant (when your role may)
Deny — block the call
Destructive tools such as delete_rows show an extra warning before rows are
removed.
Your current chat mode sets the baseline. Full
access auto-approves most appenda.* tools, but paid integrations and some
destructive paths can still prompt.
Two policy layers
Settings → Permissions — per role: Deny / Require approval / Allow for
tool classes (tables, fields, list import, enrichment, agent filesystem,
agent terminal)
Runtime cards — per call when Require approval applies or the chat mode
is Ask / Read only
Chat modes set session posture. Permissions set workspace ceilings.
Paid integrations and enrichment
Integration runs, enrichment columns, and list import jobs need a preview step
and a separate approval before credits or provider HTTP runs.
Settings → Agents
Workspace admins also manage:
Pending approval requests from members who need an admin decision
Saved approvals (durable grants you can revoke)
Provider sign-in status lives on the same Agents settings page but is covered
in Sign-in.
What is the difference between Allow once and Allow for session?
Allow once runs that single tool call. Allow for session remembers the same tool for this chat tab until you close it or change mode.
What does Always allow do?
It saves a durable grant your workspace can reuse. Roles with grant approvals may create these from a card. Admins can revoke saved approvals under Settings → Agents.
Why do I still see cards in Full access?
Full access widens the session default. Paid integrations, enrichment runs, list import, and destructive deletes can still pause. Workspace Deny and Require approval rules also apply.
Who resolves pending approval requests?
Members with grant approvals or workspace admins review requests under Settings → Agents. Until someone approves, the agent turn stays paused.