Skip to content
rev0Docs

Approve a tool request

When an agent reaches for a tool or a command outside its pre-approved set, the run pauses and the ticket moves to Pending Action until you answer. You end with the agent carrying on (or told why not), and, if you choose, never asked about that command again.

Why the board asks is in The permission gate.

  • A ticket in Pending Action whose banner reads Agent needs permission. The card on the board says needs permission.

The approve or decline panel for npm install csv-writer, with the agent's justification above the buttons Allow once, Allow all commands this session, Always allow this command, Always allow all npm install commands and Deny

  1. Open the ticket and click Review request ↓ in the banner. The panel sits under the agent’s request in the timeline: The agent is asking to run a command. Approve or decline: (or …to use a tool), with The agent justification and the command. Read any warning on it: Irreversible, Flagged because: …, or the files it Deletes.
  2. Pick one:
    • Allow once: this one call.
    • Allow for the rest of this session (Allow all commands this session for a shell command): every such call until the ticket starts a fresh agent session. A session survives replies and resumes; a restart from scratch ends it.
    • Always allow this tool or Always allow this command: persisted across all future runs of every ticket, which adds it to an allow list (see Permission lists). For an MCP tool, Always allow all … tools covers the whole server; for a command, Always allow all … commands covers its family (for example every npm install).
    • Deny, with an optional reason (Optional reason when denying…) that is sent back to the agent.

Result: whichever you pick, the ticket goes back to To Do and the runner resumes the agent: with the tool if you allowed it, with your reason if you denied it.

Board actions an agent asks the board itself to take are approved per session only, so their panel says Board actions are approved per session, never permanently. and offers no always option.

You can also answer from Catch up without opening the ticket: its card offers Allow once, a session option, Always allow and Deny (the family and whole server options are only on the ticket). See Answer what the board asks you.

Every grant you gave on a ticket is listed on it, so you can undo one you regret.

  1. Open the ticket and find the Allowed permissions section. Each row reads Run … or Use …, with its scope: once, this session, always, always (family) or always (whole server).
  2. Click Remove on the row (or Remove grant on the decision in the timeline).
  3. Confirm Remove.

Result: the grant is gone and the agent has to ask again the next time. For an always grant, the entry is also taken off the board wide allow list, so no other ticket gets it either.

Always allow is the quick way. To manage the lists directly, or to ban something outright, use Settings > Security: Command permissions for shell commands and Tool & MCP permissions for tools, including mcp__<name>__* for a whole MCP server.

  1. Open Settings > Security > Command permissions.
  2. Click + Add command, type the command prefix (for example npm install) and set it to Allow (runs without asking), Ask (always asks you) or Deny (blocked outright). Deny beats Ask, and Ask beats Allow.
  3. Click Save.

Every Always allow you clicked is a row here; remove a row to take it back. A dangerous command (a recursive delete, sudo, git push) is never approved by the built in safe baseline: to let one through without asking, set it to Allow here.

Result: the next time an agent runs a command under that prefix, it runs (or is refused) without a panel.

Check the ticket’s engine. Runs on Cursor, and on Codex with the older exec transport, are not gated by the board: their commands never reach this panel. The ticket shows an Engine parity comment when that is the case. See The permission gate.