Skip to content

Approve requests in the web app

When an agent’s action matches an Ask rule, the gate holds it and the request shows up on Approvals. It waits there until enough people decide, or until it expires.

  • Waiting lists the requests that still need a decision. For me shows the ones for your teams; Everyone shows all of them.
  • Decided lists approved, denied and expired requests, with who decided and when.

When a change to the rules waits for a second admin, Waiting also shows Agent requests and Admin changes. See admin changes.

  • The request, exactly as the gate captured it: method, host and path, and under Request details the headers and body, with secrets masked.
  • The matched rule, and who started the agent: the person, the Linux user and the agent. Started as shows the command the session was started with.
  • Why the agent asks, when your organization has it on: a short summary of what the agent said just before the request, written by your organization’s Claude integration, with personal data masked. It is the agent’s own explanation and can be wrong. What you approve is the request above it.
  • Approvals: how many people from which team must approve, and each person’s answer.
  • Expires: when the request runs out if nobody decides.
  1. Open the request.
  2. Optionally write a reason. It is saved in the audit log with your decision.
  3. Click Approve or Deny.
  • One Deny is enough. The request is denied at once, and the agent gets the answer “This was denied by” and your name.
  • Approvals add up. When the rule needs more people, the request keeps waiting: “You approved. It still waits for more people.”
  • Approved: the gate gets a signed permit. The request runs once, on the agent’s next try, within 15 minutes. After that the permit expires and the agent has to ask again.
  • Decisions are final. Nobody can change them later.

When you cannot approve, the request says why, for example because you started the agent (see who approves). Sometimes you can still deny it.

A request with no decision expires after 24 hours. Expired counts as denied: the action does not run.

An agent that sends the same action again while it waits joins the waiting request; it does not open a new one. Started by then lists every session that waits on it.

A request marked TEST · nothing will run comes from a rule test: someone checks that requests for a rule reach you and that you can answer. Answer it like any other request. No agent waits and no permit is made.