Skip to content
Browse all documentation

Reference · 8 min read

Permissions and approvals

Use Auto-approve or Ask while keeping destructive, external, and unrestricted actions controlled.

On this page
  1. Auto-approve
  2. Ask before actions
  3. Connectors and remote systems
  4. Sandbox boundaries

Auto-approve

Auto-approve lets eligible routine actions continue in a trusted project without stopping at every card.

It is not a global bypass. Security-tool installation, unrestricted sandbox escape, destructive or open-world connector actions, and other hard-consent operations still require a decision.

Ask before actions

Choose Ask to inspect eligible operations. Rejecting one request does not reject unrelated pending requests in the task.

Reject unexpectedly broad paths, unresolved variables, destructive flags, or external destinations and ask Gyroscape to narrow the action.

Connectors and remote systems

Connector tools describe whether actions are read-only, destructive, idempotent, or open-world. Unannotated actions are treated conservatively, and destructive or open-world requests require hard consent.

Approval covers the displayed action, not a general right to act on the connected account.

Sandbox boundaries

The active project is the normal boundary. Access outside it, system changes, and unrestricted commands can require escalation. Gyroscape resolves exact targets and prefers recoverable operations where practical.