Approvals

Approvals is a governance queue where Superusers review and approve or reject sensitive requests from workspace members. Requests carry a risk rating—and, for work sessions, an AI pre-review—to help reviewers decide quickly and safely.

Note: Approvals is available to users with the Superuser role. A separate Approval history view (under Audit) shows past decisions.

What goes through approvals

Several kinds of sensitive requests route here:

  • Work session and work session modification
  • Service token and token modification
  • Username and group name changes

What an approver sees—and what they can adjust—differs by type. See Request types. For the reviewer-side journey end to end, see The approver’s guide.

The approvals queue

Open Pending approvals in the sidebar. Each request shows its type, the requested data, who requested it, and its status:

StatusMeaning
PendingAwaiting a decision
ApprovedApproved by a reviewer
RejectedRejected by a reviewer
CanceledWithdrawn by the requester
ExpiredTimed out before a decision

Filter the queue by status—All, Pending, Resolved, or Expired & canceled—and by request type, or search across requests.

For how to open and act on a request, see Reviewing requests.

Who can approve

Reviewing the queue requires the Superuser role. More than one person can hold this role, and any of them can review any pending request. The Admin role can’t approve requests, and members without the Superuser role can’t open the queue at all. The managers of a request’s servers are notified of a pending work session but can’t approve it themselves.

A request can’t be approved through the same channel it was submitted from—for example, a request made from the CLI is approved in the Approvals queue of the web console (or via Slack), never from the CLI itself. So you track your own request’s status (for example, from your dashboard) until a Superuser decides. Slack one-tap approvals carry the same Superuser requirement.

Automatic approval

Some requests clear without waiting for a manual decision:

  • A Superuser’s own session request is approved as soon as it’s made.
  • Sessions requested by an AI agent always require human approval, even when a Superuser makes the request.
  • Workspaces can configure approval policies that decide, based on a request’s risk and who is asking, which actions clear automatically and which wait for a person to review.

Approval history

Resolved requests are available in Approval history under Audit > Governance, where you can review past approve and reject decisions.

Last updated: