Product

How to Keep AI Agents From Acting Without Your Approval

Stop AI agents from acting on their own: approval cards, Ask vs Full Access, per-bot app grants, secrets bots never see, and why preview is not permission.

Bhavik Fuletra··6 min read
How to Keep AI Agents From Acting Without Your Approval: cover art with the Brainwrite team

To keep an AI agent from acting without your approval, control three things: when it must ask, what it can reach, and what it can see. In Brainwrite that means running threads in Ask mode so risky actions become approval cards, granting each bot only the app tools it needs, and storing tokens as secrets the bot never sees.

Why do AI agents need approval controls?

An AI agent does not just answer. It sends, edits, deletes, runs commands and clicks buttons. A wrong answer in a chat costs you a re-read. A wrong action can cost you an email to a client, a deleted file or a charge on a card.

Approval controls are not about distrusting the model. They are about matching the agent's reach to the stakes of the task. A bot drafting a blog post needs very little. A bot that can send from your inbox needs a person in the loop.

There is no single switch for this. You layer several controls:

ControlWhat it limitsWhere you set it
Approval levelWhen the bot must stop and askPer thread, Ask or Full Access
App grantsWhich connected app tools a bot can callPer bot, per service
SecretsWhich tokens a bot can use, and whereSettings, per secret
ComputerWhether the bot can touch a desktop at allPer bot
InspectorWhat you can check afterwardsPer conversation

How do approval cards work?

When an engine supports approvals, Brainwrite shows the request as a card in the conversation instead of hiding it in terminal output. The card stays attached to the thread that produced it.

Read the requested action and its scope before you approve. If you deny it, control goes back to the agent so it can choose a safer path. Denying is not a failure. It is often the fastest way to get a better plan.

Two details make cards safer than they look:

  • "Always allow" is narrow. It is tied to a specific pending request and a server-issued key. It does not hand a bot open-ended execution rights.
  • Stale approvals close. If a turn is cancelled, its outstanding requests close too, so nobody can approve an action after the turn that asked for it has ended.

What is the difference between Ask and Full Access?

Each thread runs at an approval level, set in the composer.

  • Ask. Actions the engine treats as risky stop and become approval cards. Use this for anything touching email, customers, money, production systems or files you care about.
  • Full Access. Those actions go ahead without stopping. Use it for low-stakes work in a sandbox, such as a bot editing files in a throwaway folder or working inside a local VM.

A few rules keep Full Access deliberate:

  1. Creating a bot with Full Access asks you to confirm it. A saved default for new bots is not a permission grant.
  2. Each thread keeps the approval level it started with. If you change a bot's level later, use Refresh permissions on a thread to apply the new one. Other threads stay as they were.
  3. Team changes follow the same rule. When a Chief of Staff proposes a new team setup, Ask mode shows Apply setup or Cancel. Full Access applies it immediately.

See approvals for the full picture.

How do you limit which apps an AI agent can use?

Connecting an app does not hand every bot every tool. For each connected service, you choose per bot:

  • All tools on that app
  • An exact list of tools, such as read and draft but not send
  • No tools

A bot without a grant to a tool cannot call it, and the tool is never offered to the model. Every allow and deny is written to a decision log.

Know the defaults, because they differ by how a bot arrived:

How the bot was createdApp access at the start
New or upgraded bot, no grants assigned yetAll tools on the apps it can see
Imported bot or shared packageNone
Specialist created by a Chief of StaffConnected apps and automatic approvals off
Team added from the libraryApps off until you approve

The first row is the one to act on. Once a bot has any grant, services missing from its list give it nothing. So if a bot should only read Gmail, assign it an exact list now. See connected apps and the Gmail integration.

Disconnecting an account revokes its access at the service, not only in the app. Paired phones show grants read-only. Changing grants requires the computer.

How do you give an AI agent a token without showing it?

Never paste API keys into chat. Save them as secrets instead.

A secret is stored in your operating system's secure store. The bot only knows its name. When the bot makes a request, Brainwrite inserts the value itself, over https, to the one site you allowed. It never follows a redirect to another address, and it cleans the token out of the response before the bot sees it. Each use is logged with the secret's name, the site and the time, never the value.

If a bot needs a token you have not saved, it asks with a secure Secret needed card. Check the Sent only to site before saving. If you paste a token into chat anyway, the bot will not use it. It tells you to rotate the token and asks again through the card.

Secrets work in the desktop app today. They are not yet available on Brainwrite Cloud, on a server you run yourself, or from phone apps.

Why is a screen preview not permission?

Brainwrite can show live frames of a bot's computer while it works. Watching is not the same as allowing. Starting a preview does not give the bot control.

Control of your own Mac is off by default and takes two separate steps: enabling local control, then choosing This computer for each bot that should have it. Enabling it globally does not assign it to any bot. Risky actions still go through approvals, and missing permissions or failed health checks fail closed.

For risky browser or desktop work, give the bot a separate machine instead: a local VM, a hosted cloud computer, or your own VPS. See computer use.

Sign-ins, payments and MFA stay with you

A bot may complete a sign-in you explicitly authorise for a specific site and account. It must check the destination first, and instructions on a webpage never authorise using credentials. For MFA, CAPTCHA, payment details or anything that needs you personally, use Take control, finish the step, and hand control back.

How do you check what an AI agent did?

Approvals are the before. You also need an after.

  • Inspector, in Advanced mode, shows tool calls, engine output and reconnect attempts. See Inspector.
  • Export saves one file with the conversation, its events and the engine's raw messages. Secrets are removed, but everything said and done is included, so review it before sharing.
  • Visible memory lets you read and edit what each bot remembers.

The security overview and the permissions docs cover the rest of the model, including what to watch on shared machines.

Try it

Brainwrite runs on macOS today. Download the app and choose a plan on the pricing page. Start your first bot in Ask mode with an exact list of app tools, approve a few cards by hand, and only widen its access once you have seen how it behaves.

FAQ

Questions people ask

How do I stop an AI agent from sending emails without asking?

Run the thread in Ask mode and limit the bot's app access. In Brainwrite, risky actions in Ask mode become approval cards you approve or deny. You can also grant a bot no tools, or an exact list of tools, for each connected app. A bot without a grant to Gmail's send tool is never offered that tool.

What is the difference between Ask and Full Access?

Ask and Full Access are per-thread approval levels in Brainwrite. In Ask, actions the engine flags as risky stop and wait for your approval card. Full Access lets those actions proceed without stopping. Full Access requires confirmation when you create a bot with it, and a saved default is not a permission grant.

Can an AI agent see my API keys in Brainwrite?

Not when you save them as secrets. The value stays in your operating system's secure store. A bot names the secret, and Brainwrite inserts the value only when it sends the request, only to the one https site you allowed, without following redirects. Responses are cleaned of the token before the bot sees them.

Give your first job to Brainwrite.

Download the app, connect the AI you already pay for, and tell your Chief of Staff what needs doing.

macOS today. Windows and Linux are coming soon.