Approve Before They Act
Approvals let you stay in control of sensitive actions. Set the same control for every employee who can use a tool, then approve or reject the requests that reach you.
TL;DR
Control Officer sets whether each tool asks first for your whole workspace. Approval and choice cards appear in chat when an employee needs your decision. Change one tool here or in its drawer, then review the approval activity and cost cards at the bottom.
How It Works
There are two types of requests employees can make:
| Type | When it triggers | What you see |
|---|---|---|
| Approval | Employee is about to take a sensitive action (send email, publish content, delete data) | Approve / Reject buttons in a card |
| Choice | Employee needs your preference on something (which platform, which format, which audience) | Multiple option buttons in a card |
Three ways approval gates get triggered:
| Method | How | Example |
|---|---|---|
| Per-tool setting | You set a tool to Ask first in Control Officer or its Approvals drawer section | Every employee using that tool pauses for your sign-off, first time in a conversation |
| Duty-based | You give the employee a duty that requires asking first | A duty says "always get approval before contacting clients" |
| Conversation-based | The employee uses judgment based on context and your instructions | You say "always check with me before sending anything external" |
All three work the same way. The employee pauses, you get notified, you decide, they continue.
Some tools ship set to ask first by default. You can change every active tool from one place. Approval only asks once per conversation for a given tool: after you approve it the first time, the employee keeps using that tool for the rest of that conversation without asking again. A rejection is never remembered the same way, so the employee still has to ask again next time.
For rules about whether an employee may disclose information it already knows, see Information Boundaries. That is separate from action approval.
The full flow:
| Step | What happens |
|---|---|
| 1. Employee hits a gate | A sensitive action or preference decision requires your input |
| 2. Employee pauses | Execution stops immediately. Status changes to "Awaiting Input" |
| 3. You get notified | A notification appears. An inline card appears in the chat with the action details |
| 4. You decide | Click Approve, Reject, or select an option |
| 5. Employee resumes | Work continues instantly from exactly where it stopped |
Zero cost while waiting. No tokens are consumed, no background processes run, and no credits are charged while the employee waits for your decision. The pause survives system restarts.
Where to Find It
Control Officer is the workspace-wide control panel:
- Open Settings > Technical > Control Officer
- Tools are grouped as Apps & integrations, Utilities, and collapsed Internal system tools
- Turn a tool on to make it Ask first, or off for Don't ask
- The setting applies to every employee who uses that tool, not just the employee you selected
Ask-first tools stay at the top of each group. Use the tool drawer's Approvals section when you are already inspecting one tool. It changes the same shared setting.
At the bottom, Approval activity shows all employee tool calls, asks, approvals, rejections, pending requests, and recent decisions. Officer cost confirms that Control Officer itself is completely free. Only workspace admins can view this tenant-wide activity.
Approval cards appear inline in the chat when an employee requests your input:
- Go to your Workspace
- Click on the employee who requested approval
- Scroll to the approval card in the chat conversation
You can also respond from the notification panel (bell icon in the top bar) without opening the chat.
What You Can Do
| Action | How |
|---|---|
| Approve an action | Click Approve on the inline card in chat, or from the notification panel |
| Reject an action | Click Reject. The employee skips the action and continues their workflow |
| Pick an option | Click one of the option buttons on a choice request |
| Review action details | The inline card shows the action name, details, and reason. Open the detail drawer from the notification for full context |
| Jump to the tool's permission | An approval card for a tool shows a Change permission link that opens the Tools tab, scoped to that tool |
| Set up approval duties | Give employees a duty like "always get approval before contacting clients" |
How to Set It Up
For all employees who use a tool (recommended):
- Go to Settings > Technical > Control Officer
- Find the tool, then turn on Ask first
- Done. Every employee using that tool now pauses and asks the first time it uses it in a conversation
From a tool drawer:
- Open an employee's Tools tab and select the tool
- Open Approvals
- Turn on Ask first or add rules for that tool
- The shared setting updates in Control Officer too
For duty-based approval (recommended for a general policy):
- Go to an employee's Duties tab
- Click Create Duty or Browse Duties
- Add a duty like "Always get my approval before sending emails to external contacts"
- Done. The employee will request approval when the duty applies
For conversation-based approval:
Simply tell the employee in chat: "Always check with me before sending anything external." The employee will remember and request approval in future interactions.
Tips and Tricks
- Use Control Officer for workspace-wide control. It lists every active tool, keeps ask-first tools on top, and applies the choice to every employee using that tool
- Use the tool drawer for a single-tool shortcut. Its Approvals section edits the same workspace-wide setting
- Use duties for a general policy. A duty like "always get approval before contacting clients" covers a category of action, not just one tool
- Check notifications regularly. A pending approval blocks the employee from continuing that specific workflow
- Respond quickly for scheduled work. If a scheduled task triggers an approval, the employee waits until you respond. Check notifications so scheduled work does not stall
- Rejection is not an error. When you reject, the employee skips the action and continues their workflow normally. They will not re-request the same action
- The inline card has full context. The approval card shows what the employee wants to do and why, so you can make an informed decision without digging
Good to Know
- Zero cost pause. While waiting for your decision, nothing runs. No tokens, no background processes, no credits
- Durable wait. The pause survives system restarts. Your employee will still be waiting even if the server reboots
- Time awareness. When you respond after a delay, the employee is told how much time passed. After a long delay (hours or days), they reassess whether the action is still relevant before proceeding
- A stale request gets one reminder. If you have not responded after 48 hours, you get a second notification, then again every 24 hours until you decide
- Deduplication built in. If the employee accidentally requests the same approval twice (e.g., from a scheduled heartbeat), the system detects the duplicate and only shows one request
- Page reload recovery. If you refresh the page while an approval is pending, the buttons reappear automatically
- Chained approvals. An employee can hit multiple approval gates in a single workflow. Each one pauses, waits, resumes, and continues to the next
Frequently Asked Questions
Q: What happens if I reject an action? A: The employee skips the rejected action and continues their workflow normally. They update tasks, write journal entries, and respond to you as usual. They will not re-request the same action.
Q: Does the employee cost me credits while waiting? A: No. Zero tokens are consumed and zero credits are charged during the pause.
Q: Can I approve from the notification panel without opening the chat? A: Yes. The notification shows Approve/Reject buttons. Click directly from there.
Q: What if I do not respond to an approval request? A: The employee stays paused indefinitely until you respond. There is no automatic timeout, but you get a reminder notification after 48 hours and then every 24 hours.
Q: Can I see what the employee wants to do before approving? A: Yes. The inline card in chat shows the action name, details, and reason. For more context, open the detail drawer from the notification panel.
Q: How do I make every employee ask before using one tool? A: Open Settings > Technical > Control Officer, find the tool, and turn on Ask first. The same setting is available in the tool drawer's Approvals section.
Q: What do the Control Officer activity numbers mean? A: Tool calls are recorded when employees run tools. Asked first, approved, rejected, and waiting come from approval requests. Rejected and pending requests remain visible even though they did not execute.
Q: Do I have to approve the same tool every time? A: No. A tool set to "Requires approval" asks once per conversation. After you approve it the first time, the employee keeps using it for the rest of that conversation without asking again.