Skip to main content
Approval rule: humans decide. Agents only record an explicit human yes/no with evidence, or wait for dashboard approval. Agents never approve their own requests.

The loop

1

Request

2

Get a human decision

Ask in chat, or point them at the approvals page from dench context --json (approvalsUrl).
3

Record it with evidence

Actions to review in ask mode

Shipping

Merging a PR, deploying, or changing production data.

Money

Spending money or issuing refunds.

Outbound

Sending external email or messages.

Infra & secrets

Creating or modifying infrastructure, or accessing secrets.
Read-only tool actions don’t need approval. In ask mode, non-read-only integration actions use the approval loop. See Integrations.
For Dench-brokered Slack, Gmail, Outlook, Calendar, and LinkedIn tools, workspace Full access (yolo) skips the approval gate. Authentication and connection access checks still apply. Switching the workspace from ask to Full access takes effect on the next tool call, without creating an approval request or changing existing approval records. Agents must not record a human decision just to make a YOLO tool call run.