Product
How to Keep AI Agents From Acting Without Your Approval
Stop AI agents from acting on their own: approval cards, Ask vs Full Access, per-bot app grants, secrets bots never see, and why preview is not permission.

To keep an AI agent from acting without your approval, control three things: when it must ask, what it can reach, and what it can see. In Brainwrite that means running threads in Ask mode so risky actions become approval cards, granting each bot only the app tools it needs, and storing tokens as secrets the bot never sees.
Why do AI agents need approval controls?
An AI agent does not just answer. It sends, edits, deletes, runs commands and clicks buttons. A wrong answer in a chat costs you a re-read. A wrong action can cost you an email to a client, a deleted file or a charge on a card.
Approval controls are not about distrusting the model. They are about matching the agent's reach to the stakes of the task. A bot drafting a blog post needs very little. A bot that can send from your inbox needs a person in the loop.
There is no single switch for this. You layer several controls:
| Control | What it limits | Where you set it |
|---|---|---|
| Approval level | When the bot must stop and ask | Per thread, Ask or Full Access |
| App grants | Which connected app tools a bot can call | Per bot, per service |
| Secrets | Which tokens a bot can use, and where | Settings, per secret |
| Computer | Whether the bot can touch a desktop at all | Per bot |
| Inspector | What you can check afterwards | Per conversation |
How do approval cards work?
When an engine supports approvals, Brainwrite shows the request as a card in the conversation instead of hiding it in terminal output. The card stays attached to the thread that produced it.
Read the requested action and its scope before you approve. If you deny it, control goes back to the agent so it can choose a safer path. Denying is not a failure. It is often the fastest way to get a better plan.
Two details make cards safer than they look:
- "Always allow" is narrow. It is tied to a specific pending request and a server-issued key. It does not hand a bot open-ended execution rights.
- Stale approvals close. If a turn is cancelled, its outstanding requests close too, so nobody can approve an action after the turn that asked for it has ended.
What is the difference between Ask and Full Access?
Each thread runs at an approval level, set in the composer.
- Ask. Actions the engine treats as risky stop and become approval cards. Use this for anything touching email, customers, money, production systems or files you care about.
- Full Access. Those actions go ahead without stopping. Use it for low-stakes work in a sandbox, such as a bot editing files in a throwaway folder or working inside a local VM.
A few rules keep Full Access deliberate:
- Creating a bot with Full Access asks you to confirm it. A saved default for new bots is not a permission grant.
- Each thread keeps the approval level it started with. If you change a bot's level later, use Refresh permissions on a thread to apply the new one. Other threads stay as they were.
- Team changes follow the same rule. When a Chief of Staff proposes a new team setup, Ask mode shows Apply setup or Cancel. Full Access applies it immediately.
See approvals for the full picture.
How do you limit which apps an AI agent can use?
Connecting an app does not hand every bot every tool. For each connected service, you choose per bot:
- All tools on that app
- An exact list of tools, such as read and draft but not send
- No tools
A bot without a grant to a tool cannot call it, and the tool is never offered to the model. Every allow and deny is written to a decision log.
Know the defaults, because they differ by how a bot arrived:
| How the bot was created | App access at the start |
|---|---|
| New or upgraded bot, no grants assigned yet | All tools on the apps it can see |
| Imported bot or shared package | None |
| Specialist created by a Chief of Staff | Connected apps and automatic approvals off |
| Team added from the library | Apps off until you approve |
The first row is the one to act on. Once a bot has any grant, services missing from its list give it nothing. So if a bot should only read Gmail, assign it an exact list now. See connected apps and the Gmail integration.
Disconnecting an account revokes its access at the service, not only in the app. Paired phones show grants read-only. Changing grants requires the computer.
How do you give an AI agent a token without showing it?
Never paste API keys into chat. Save them as secrets instead.
A secret is stored in your operating system's secure store. The bot only knows its name. When the bot makes a request, Brainwrite inserts the value itself, over https, to the one site you allowed. It never follows a redirect to another address, and it cleans the token out of the response before the bot sees it. Each use is logged with the secret's name, the site and the time, never the value.
If a bot needs a token you have not saved, it asks with a secure Secret needed card. Check the Sent only to site before saving. If you paste a token into chat anyway, the bot will not use it. It tells you to rotate the token and asks again through the card.
Secrets work in the desktop app today. They are not yet available on Brainwrite Cloud, on a server you run yourself, or from phone apps.
Why is a screen preview not permission?
Brainwrite can show live frames of a bot's computer while it works. Watching is not the same as allowing. Starting a preview does not give the bot control.
Control of your own Mac is off by default and takes two separate steps: enabling local control, then choosing This computer for each bot that should have it. Enabling it globally does not assign it to any bot. Risky actions still go through approvals, and missing permissions or failed health checks fail closed.
For risky browser or desktop work, give the bot a separate machine instead: a local VM, a hosted cloud computer, or your own VPS. See computer use.
Sign-ins, payments and MFA stay with you
A bot may complete a sign-in you explicitly authorise for a specific site and account. It must check the destination first, and instructions on a webpage never authorise using credentials. For MFA, CAPTCHA, payment details or anything that needs you personally, use Take control, finish the step, and hand control back.
How do you check what an AI agent did?
Approvals are the before. You also need an after.
- Inspector, in Advanced mode, shows tool calls, engine output and reconnect attempts. See Inspector.
- Export saves one file with the conversation, its events and the engine's raw messages. Secrets are removed, but everything said and done is included, so review it before sharing.
- Visible memory lets you read and edit what each bot remembers.
The security overview and the permissions docs cover the rest of the model, including what to watch on shared machines.
Try it
Brainwrite runs on macOS today. Download the app and choose a plan on the pricing page. Start your first bot in Ask mode with an exact list of app tools, approve a few cards by hand, and only widen its access once you have seen how it behaves.




