Approvals
Approvals is a governance queue where Superusers review and approve or reject sensitive requests from workspace members. Requests carry a risk rating—and, for work sessions, an AI pre-review—to help reviewers decide quickly and safely.
Note: Approvals is available to users with the Superuser role. A separate Approval history view (under Audit) shows past decisions.
What goes through approvals
Several kinds of sensitive requests route here:
- Work session and work session modification
- Service token and token modification
- Username and group name changes
What an approver sees—and what they can adjust—differs by type. See Request types. For the reviewer-side journey end to end, see The approver’s guide.
The approvals queue
Open Pending approvals in the sidebar. Each request shows its type, the requested data, who requested it, and its status:
| Status | Meaning |
|---|---|
| Pending | Awaiting a decision |
| Approved | Approved by a reviewer |
| Rejected | Rejected by a reviewer |
| Canceled | Withdrawn by the requester |
| Expired | Timed out before a decision |
Filter the queue by status—All, Pending, Resolved, or Expired & canceled—and by request type, or search across requests.
For how to open and act on a request, see Reviewing requests.
Who can approve
Reviewing the queue requires the Superuser role. More than one person can hold this role, and any of them can review any pending request. The Admin role can’t approve requests, and members without the Superuser role can’t open the queue at all. The managers of a request’s servers are notified of a pending work session but can’t approve it themselves.
A request can’t be approved through the same channel it was submitted from—for example, a request made from the CLI is approved in the Approvals queue of the web console (or via Slack), never from the CLI itself. So you track your own request’s status (for example, from your dashboard) until a Superuser decides. Slack one-tap approvals carry the same Superuser requirement.
Automatic approval
Some requests clear without waiting for a manual decision:
- A Superuser’s own session request is approved as soon as it’s made.
- Sessions requested by an AI agent always require human approval, even when a Superuser makes the request.
- Workspaces can configure approval policies that decide, based on a request’s risk and who is asking, which actions clear automatically and which wait for a person to review.
Approval history
Resolved requests are available in Approval history under Audit > Governance, where you can review past approve and reject decisions.