Skip to content

Why the agent asks

When a request waits for approval, approvers see Why the agent asks: one or two sentences on why the agent is about to act, written from what the agent itself said just before. The reason is the agent’s own account, shown apart from the action. It never decides anything; the action shown is what the gate captured.

  • The organization’s Claude (Anthropic) integration, under Settings › Integrations: your own Anthropic API key. Noset uses Claude Haiku to write the reasons. Without it, approvers see no reason and a link to set it up.
  • The organization setting Show approvers the agent’s reasons, under Settings › Organization. It is on by default. Turning it off applies at once; turning it on again waits for a second admin when there is one.

The gate never holds a model key: it only sends what the agent said to your Noset server.

  • What the agent’s model said. The gate already reads the agent’s traffic to the Anthropic and OpenAI APIs. It keeps, in memory only, the agent’s last steps: the text the model wrote just before a tool call, and that tool call’s input (for example the Bash command). It never reads the model’s thinking.
  • What the agent said itself. An agent can send a Noset-Reason: <text> header with the request. The gate uses it instead, and removes the header before the request goes on.

When a request is held, the gate takes the steps that belong to it, masks secrets in them and sends at most 4 KB to the Noset server.

The Noset server has the reason written in English, whatever the agent’s language, and keeps only that:

  • Names, emails, phone numbers, addresses, IP addresses, dates of birth and ids that point to a person become [name], [email], [phone], [address], [ip], [date], [id]; secrets become [secret].
  • The server checks the answer again and replaces email addresses, UUIDs, IP addresses, phone numbers and stand-alone numbers of four or more digits itself.
  • What the agent said is never stored or logged. The evidence chain records only a hash of the reason.

Approvers also see Started as: the command the session was started with, masked the same way.

  • No Claude integration, or writing the reason failed: approvers see that there is no reason, and why.
  • The setting is off: the gate sends nothing, and approvers see a link to the setting.
  • No step matched the request: the request shows no reason.