Each action gets one of three permission levels
Every tool the agent can reach carries a label. Automatic actions run straight away, approval actions pause until a person clicks, and forbidden actions never run. An action that is missing from the list counts as forbidden.
| Level | Usual examples | What happens |
|---|---|---|
| Automatic | Lookups and order-status answers | The agent acts and writes a log row |
| Needs approval | Refunds, cancellations, outbound messages | The agent prepares it and waits for a person to click |
| Forbidden | Anything not on the list | The agent has no way to call it |
The boundary is agreed before the build
The written proposal includes the permission table itself. You choose where the line sits when you accept the work, rather than after something has gone wrong.
One log row for every action
Each action leaves a single row: the role that acted, the tool it used, the time, the outcome and the person who approved it. You can read back anything the agent did and correct it.
The log is kept on your own accounts and written in everyday language, so reading it does not depend on us.
When a script is the safer choice
Some tasks follow fixed rules and need no judgment. Where a plain script would be safer than an agent, the reply says so and the script is what gets built. Agents are kept for decisions that call for judgment inside set limits.
How approvals fit into the wider project is covered in how engagements run.