Control and security

Nothing risky happens until you say yes

Approvals in Brainwrite turn an agent's risky actions, questions and permission requests into cards in the conversation, where you read the action and its scope before allowing it. Each thread runs in Ask or Full Access mode. Denying an action hands control back to the agent so it can choose a safer path, and Always allow stays narrow instead of granting blanket permission.

A refund in Ask mode

Handle the refund request from the Northwind Studio support inbox.

Your Chief of Staff put a team on it

  • Atlas· Keeper, Sales Operations Analyst
  • Sage· Nudge, Follow-up Writer
  • Order #2291 is within the 14-day refund window.
  • Drafted a reply to the customer.
  • Wants to issue a $49 refund in Stripe. Approval card shown with the amount.

DoneApprove or deny the $49 refund: waiting for your yes.

An illustrated example. Your team works on your own files and apps.
A shop owner packs a ceramic mug into a box as two illustrated Brainwrite AI agents, Nova and Dash, report back from her packing table.
NovaChief of StaffMorning run done
DashOrders14 replies drafted
NovaChief of Staff
9:02 am

A refund in Ask mode: done. One thing waits for you.

  1. 1Order #2291 is within the 14-day refund window.
  2. 2Drafted a reply to the customer.
  3. 3Wants to issue a $49 refund in Stripe. Approval card shown with the amount.
2 bots on this job
Approve or deny the $49 refundWaiting for your yes

See it in the app

Approvals in Brainwrite.

Keeper asking to create a Gmail draft to a prospect; the approval card shows the draft and Deny, Always allow this session and Allow once.

Why it matters

On your own, with a chatbot, and with Brainwrite.

Doing it yourselfA single chatbotBrainwrite
Risky stepsYou do them by handIt suggests; you carry it out elsewhereThe agent prepares the step; it waits as an approval card
Saying noNothing happensYou rephrase and ask againControl goes back to the agent to find a safer path
Standing permissionNot applicableDepends on the productAlways allow is narrow, tied to one pending request
Record of decisionsYour memorySomewhere in the chatThe card and its outcome stay with the task that asked

How it works

How Approvals works.

  1. 01

    Choose the mode

    Set Ask or Full Access for a thread in the composer. Each thread keeps the approval level it started with.

  2. 02

    Read the card

    When a supported engine asks permission, the request appears as a card attached to the task that produced it, not buried in terminal output.

  3. 03

    Approve or deny

    Approve to continue, or deny to send control back so the agent can try a safer way.

  4. 04

    Refresh after changes

    After changing a bot's approval level, open a thread's … menu and choose Refresh permissions to apply it there. Other threads stay as they are.

Good to know

The details.

Always allow is narrow

It is tied to a server-issued key and the pending request, not to arbitrary execution.

No stale approvals

Cancelling a turn closes its outstanding requests, so an old card cannot be answered after the turn has ended.

Specialists start careful

A specialist created by a Chief of Staff starts with connected apps and automatic approvals off.

Defaults are not grants

A saved default for new bots never grants Full Access or local-computer Auto by itself. Both still need confirmation when the bot is created.

Approvals out loud

During a voice call, approval requests can be narrated so long-running work does not go quiet.

Scheduled runs wait

A routine run that needs approval shows as waiting until you answer. Open run takes you to the card.

The edges, plainly

  • Approval cards appear when the engine supports approvals, and engines differ in what they report.
  • Full Access does not ask before protected actions, so keep it for work you trust.
  • Refresh permissions is not available while the thread is working.
Full reference in the documentation

FAQ

Questions about Approvals

Can AI agents act without my permission?

In Ask mode, risky actions from engines that support approvals become cards in the conversation and wait for you. You read the action and its scope, then approve or deny. Full Access does not ask before protected actions, so choose it per thread only for work you trust.

What happens when I deny an AI agent's request?

Denying an action sends control back to the agent so it can choose a safer path. The denied action does not run. The card and its outcome stay in the conversation, attached to the task that produced it, so you can see what was asked and what you decided.

What does Always allow do in Brainwrite?

It saves a narrow approval, tied to a server-issued key and the specific pending request, rather than granting arbitrary execution. After you change a bot's approval level or saved approvals, use Refresh permissions on a thread to apply the bot's current ones there.

What is the difference between Ask and Full Access?

Ask mode stops before protected actions and shows an approval card. Full Access does not ask first; for example, team setup changes apply immediately instead of waiting for Apply setup. You choose the mode per thread in the composer, and each thread keeps the level it started with.

Give your first job to Brainwrite.

Download the app, connect the AI you already pay for, and tell your Chief of Staff what needs doing.

macOS today. Windows and Linux are coming soon.