Approvals
An ability with a hold rule, or any change under approval_required mode, does not run when the agent asks. It waits for a person.
What the agent sees#
The agent receives a pending result with an approval ID. It can call agentwarden/check-approval to learn whether the request was approved, denied, or expired, and to get the result once the action ran.
Deciding#
- Agent Warden → Approvals lists waiting actions with the agent, the ability, a plain-language summary, and the input.
- Preview effect (Pro) runs the action in dry-run mode and shows what would change.
- Approve runs the exact input the agent sent. The input is sealed when the request is made, so it cannot change while it waits.
- Deny records your note, and the agent sees it.
Who can decide#
By default, any administrator. Per agent, Approver routing limits decisions to the agent's owner or to a list of people.
Notifications (Pro)#
Email, Slack (with Approve and Deny buttons), Microsoft Teams, and webhooks, in Settings → Approval notifications. Email links let an approver decide without signing in. Each link works once, is tied to that approver, and expires with the request.
Expiry#
Requests expire after 24 hours by default (Settings → Approvals, 1 to 168 hours). An expired request never runs; the agent can ask again.
Agency teams can also decide approvals for every site from the hub.