Skip to main content
A permission level decides what happens when the agent is about to do something. It never changes what the agent is able to do. The same tools are available at every level. What changes is who gives the go-ahead.

The three levels

Ask for approval

The agent asks before reading, editing or sending anything.Every action that touches your data pauses for your approval.

Approve for me

A safety review screens sensitive actions and only asks you about the ones it holds back.The default. Reading and tracked edits run. Sensitive actions are reviewed first.

Full access

The agent skips permission prompts and the safety review.Built-in checkpoints, like plan approval and sharing outside the organization, still ask.

What each level does, by risk tier

Every tool has a risk tier. This table is the whole rule.

The safety review

At Approve for me, each sensitive action is examined by a separate, fast AI reviewer before it runs. The reviewer decides one of three things:
The reviewer sees only four things: what you asked for, the exact action the agent wants to take, facts computed by the platform, and your organization’s guidance.It deliberately does not see the agent’s own reasoning or the contents of documents and emails the agent has read. That is where a malicious instruction would hide, so text planted in a document cannot talk the reviewer into approving something.
The action is held. A review that fails or times out never counts as an approval.
After three consecutive refusals the agent stops and checks with you: “Several actions in a row were held back, so the agent is checking with you.” This usually means the task needs a decision only you can make.
When an action is declined or held back, the agent is told not to retry it or reach the same result another way. It explains what was held and waits for you.
Reviews run on the fast, economical model and appear as their own line in your usage.

Approving an action

When the agent needs your go-ahead you see a card: The agent wants to do this, describing the action in plain words. The outcome stays on the result, so the record is clear later: approved by you, allowed for this thread, passed the safety review, declined by you, or held back by the safety review.

Where levels are set

Choose your level in Settings → Permissions. It applies to conversations you start in the dashboard and in Word.Your choice is stored in your browser, per user. On a new device or browser you start at the default, Approve for me, until you change it.

What always asks, at every level

Some checkpoints belong to the action itself and cannot be switched off:
  • Approving a plan before the agent carries it out
  • Reviewing values before Populate writes them
  • Sharing outside the organization, such as creating or building a Shared Space that invites outside parties
  • Sending email to anyone outside your organization. These are always drafts for approval.
  • Taking over a browser session, when a site needs you to sign in
  • Proposed changes to records from email

Choosing a level

You do not have to choose once and for all. Stay on Approve for me, and use Always allow in this thread when a particular conversation involves many repeated actions of the same kind.
Whatever the level, remember the two protections beneath it: the agent can only reach what you can reach, and edits to existing documents are tracked changes you can reject.