Skip to main content
Open source Require approval for tools that change data, contact users, or reach external systems. The agent pauses before it calls an approval-gated tool, and a reviewer approves, edits, or denies the call from the agent inbox.

Require approval for tools

Choose where to set approvals based on how you run the agent:
  • Agent presets (recommended): Open the preset, select the Tools tab, then under Approval rules click Add rule, choose the tool, and set Manual approval to Required. Every ai.preset_agent run and chat with the preset uses these rules.
  • MCP integrations: Turn on Approval for a tool on a remote MCP integration. Approvals are not supported for stdio MCP servers.
  • ai.agent: Set tool_approvals on the action. Keys are action names, and true requires approval.
For example, give a case-triage preset an approval rule for core.cases.update_case, then run it from a workflow:
The agent pauses before it calls core.cases.update_case and waits for a decision in the inbox. A pause for a tool approval does not count toward the agent timeout. The workflow-level timeout still bounds the whole run, including approval waits.

Review tool calls in the inbox

Open Inbox from the workspace navigation. Runs waiting on a decision appear under Review required, and the sidebar badge shows how many are pending. Your workspace role needs inbox:read to open the inbox.
  1. Select a run to open its session and the pending tool call.
  2. Choose Approve, Edit + approve to change the tool arguments, or Deny with an optional reason.
  3. Click Submit.
An approved call runs and the agent continues. A denied call does not run, and the agent stops instead of retrying the tool.

Availability

Tool approvals and the agent inbox are open source. Enterprise Edition Enterprise adds:
  • Chatting with agents and approving tool calls from Slack through agent channels.
  • View agent runs on a case, which opens the inbox filtered to agent runs for that case.
  • See AI preset agent to save approval rules on a reusable agent.
  • See AI agent for the tool_approvals input on inline agents.
  • See MCP servers to require approval for MCP tools.