Grants and approvals
An agent acts in your apps only through its grants. A grant names one connection, the actions the agent may call there, and the ones that ask first. An app with no grant is out of the agent’s reach, even when your organization has connected it.
A new agent starts with no grants. You add them on the agent’s Editor tab, under Connected apps.
Add a grant
Section titled “Add a grant”- Open the agent and choose the Editor tab.
- Under Connected apps, press Add a connection.
- Pick an account. The list groups your organization’s connections under their app.
- The grant starts with all of the app’s reads. Press Reads to list them and remove any the agent shouldn’t use, or clear to remove them all. An app with no reads starts with every action instead.
- Press Add write for each write the agent may perform.
- Turn on Ask first for any write that should wait for a member.
- Press Save changes.
Apps your organization hasn’t connected are listed last, under Not connected. An owner or admin can press Connect there to connect one without leaving the editor. A member sees Ask an admin instead. See Connecting apps.
Each grant’s row shows how many of the app’s actions it allows and how many ask first. The remove button on the row drops the whole grant.
Reads, writes and ask first
Section titled “Reads, writes and ask first”Super Connect marks each action as a read or a write, and some writes as destructive.
| Kind of action | What the agent does |
|---|---|
| Read | Calls it without asking |
| Write | Calls it without asking, unless Ask first is on |
| Destructive write | Always waits for approval. A lock and Always replace the switch |
The agent can’t call an action that isn’t in its grant. Every call is checked against the grants before it runs.
Two accounts of one app
Section titled “Two accounts of one app”Two connections of the same app are two grants. You can let an agent post in one Slack workspace and only read another, or give it one of two GitHub accounts and not the other.
When an agent holds grants on two connections of one app, it must say which connection each call acts on. A call that doesn’t name one is refused and the agent is told the candidates. A call on a connection it wasn’t granted is refused.
When a grant goes stale
Section titled “When a grant goes stale”- Connection removed: the connection was disconnected. Remove the row, or add the new connection.
- No longer in the catalog: Super Connect no longer offers the app.
- No longer offered: some granted actions left the catalog. Press Remove stale to drop them.
Approvals
Section titled “Approvals”When the agent calls an action that asks first, its turn stops before the call. The call shows as Waiting for approval, with the action’s name and the input the agent wants to send.
- Approve runs the action, and the agent carries on with the result.
- Deny doesn’t run it. The agent is told it was denied and carries on without it.
Any member of the organization may decide. Approvals don’t need an owner or admin.
In chat
Section titled “In chat”The approval appears in the thread. Whoever has the thread open presses Approve or Deny. See Chatting with an agent.
In a workflow run
Section titled “In a workflow run”The Agent step waits, and every owner and admin with a verified email is sent a link to the run and to the thread. A member decides on the run page, where Deny takes an optional reason, or in the run’s thread on the agent’s Chat tab. The dashboard lists every approval that is waiting. See Runs and approvals.
A run waits 72 hours for a decision. After that the call is denied with the reason “expired without a decision”, and the step fails. See Agents in workflows.
From the API
Section titled “From the API”An organization key can decide a run’s approval with
POST /api/v1/runs/{id}/approvals/{approvalId}, sending decision as approve or deny and an
optional reason. See the API reference.
Databases and skills
Section titled “Databases and skills”Databases have their own switch. An agent can read every database you add under Databases, and writes only to those with Allow writes on. A write to a read-only database is rolled back. See Querying from agents and workflows.
Skills are instructions, not permissions. A skill can’t give an agent an action or a database it wasn’t granted. See Skills.