Documentation menu

Approvals

An ability with a hold rule, or any change under approval_required mode, does not run when the agent asks. It waits for a person.

What the agent sees#

The agent receives a pending result with an approval ID. It can call agentwarden/check-approval to learn whether the request was approved, denied, or expired, and to get the result once the action ran.

Deciding#

  • Agent Warden → Approvals lists waiting actions with the agent, the ability, a plain-language summary, and the input.
  • Preview effect (Pro) runs the action in dry-run mode and shows what would change.
  • Approve runs the exact input the agent sent. The input is sealed when the request is made, so it cannot change while it waits.
  • Deny records your note, and the agent sees it.

Who can decide#

By default, any administrator. Per agent, Approver routing limits decisions to the agent's owner or to a list of people.

Notifications (Pro)#

Email, Slack (with Approve and Deny buttons), Microsoft Teams, and webhooks, in Settings → Approval notifications. Email links let an approver decide without signing in. Each link works once, is tied to that approver, and expires with the request.

Expiry#

Requests expire after 24 hours by default (Settings → Approvals, 1 to 168 hours). An expired request never runs; the agent can ask again.

Agency teams can also decide approvals for every site from the hub.